On Dec 5, 2007, at 9:42 PM, [EMAIL PROTECTED] wrote:

>
> When testing Urchin Web Analytics v5.7.03, this plugin reports a XSS  
> issue on the login page, however I can't seem to manually reproduce  
> the error, and believe it's a false positive.


try the following request and you will see it is not a false positive :

http://serverip:9999/?";<script>alert('test');</script>



Nicolas
_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to