www.eVuln.com advisory:

"title" and "ur"l - Non-persistent XSS in Social Share

Summary: http://evuln.com/vulns/164/summary.html 

Details: http://evuln.com/vulns/164/description.html 



-----------Summary-----------

eVuln ID: EV0164

Software: Social Share

Vendor: n/a

Version: 2010-06-05

Critical Level: low

Type: Cross Site Scripting

Status: Unpatched. No reply from developer(s)

PoC: Available

Solution: Not available

Discovered by: Aliaksandr Hartsuyeu ( http://evuln.com/ )



--------Description--------

It is possible to inject xss code into "title" and "url" parameters in save.php 
script.

Parameters "title", "url" are not properly sanitized before being used in HTML 
code.



--------PoC/Exploit--------

PoC code is available at:

http://evuln.com/vulns/164/exploit.html 



---------Solution----------

Not available



----------Credit-----------

Vulnerability discovered by Aliaksandr Hartsuyeu

http://evuln.com/code-analysis.html - source code review service

Reply via email to