www.eVuln.com advisory:

"link" and "linkdescription" XSS in Social Share

Summary: http://evuln.com/vulns/165/summary.html 

Details: http://evuln.com/vulns/165/description.html 



-----------Summary-----------

eVuln ID: EV0165

Software: Social Share

Vendor: n/a

Version: 2010-06-05

Critical Level: low

Type: Cross Site Scripting

Status: Unpatched. No reply from developer(s)

PoC: Available

Solution: Not available

Discovered by: Aliaksandr Hartsuyeu ( http://evuln.com/ )



--------Description--------

It is possible to inject xss code into "link" and "linkdescription" parameters 
in processPost.php script.

Parameters "link" and "linkdescription" are not properly sanitized before being 
used in HTML code.



--------PoC/Exploit--------

PoC code is available at:

http://evuln.com/vulns/165/exploit.html 



---------Solution----------

Not available



----------Credit-----------

Vulnerability discovered by Aliaksandr Hartsuyeu

http://evuln.com/penetration-test.html - penetration testing service

Reply via email to