SecurityAlert : 1108 CVE : CVE-2006-3060 SecurityRisk : Low (About) Remote Exploit : Yes Local Exploit : No Exploit Available : Yes Credit : luny youfucktard com Published : 19.06.2006
Affected Software :
P.A.I.D v2.2
Advisory Content :
P.A.I.D v2.2
Homepage:
http://www.webexceluk.net
Effected files:
faq.php
input form of logging in.
index.php
The input forms of logging into My Account do not sanatize user input. For
PoC of a XSS attack simply put in:
"><IMG SRC=javascript:alert('XSS')><"
It also seems when logging in, even if your details are incorrect and you
browse normal parts of the site like the FAQ or the Contact Us page etc, a
message will be output in the top righton the screen with the text "Welcome
back,username", as if you were successfully logged in.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.