On Dec 5, 2007, at 9:42 PM, [EMAIL PROTECTED] wrote: > > When testing Urchin Web Analytics v5.7.03, this plugin reports a XSS > issue on the login page, however I can't seem to manually reproduce > the error, and believe it's a false positive.
try the following request and you will see it is not a false positive : http://serverip:9999/?"<script>alert('test');</script> Nicolas _______________________________________________ Nessus mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus
