- 34,644
 
- 0
 
- 18 Дек 2022
 
- EDB-ID
 - 25354
 
- Проверка EDB
 - 
	
		
			
- Пройдено
 
 
- Автор
 - ZINHO
 
- Тип уязвимости
 - WEBAPPS
 
- Платформа
 - PHP
 
- CVE
 - cve-2005-1095
 
- Дата публикации
 - 2005-04-06
 
		Код:
	
	source: https://www.securityfocus.com/bid/13046/info
Ocean12 Membership Manager Pro is reportedly affected by a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks. 
http://www.example.com/main.asp?UserID=2&page=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E%3Cfont%20color=%22&Sort=Name&DisplayNumber=10
	- Источник
 - www.exploit-db.com