Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!

TUCoPS :: Web :: CMS / Portals :: bt-21708.htm

E107 XSS
Cross-Site Scripting vulnerability in E107
Cross-Site Scripting vulnerability in E107

Hello Bugtraq!

I want to warn you about Cross-Site Scripting vulnerability in E107. Which I
found at 31.01.2009 and disclosed recently.


At page for sending news to email (http://site/email.php?news.1) it's 
possible to conduct XSS attack via Referer header. Particularly it can be
done via flash.

Referer: '>

Vulnerable are E107 0.7.16 and previous versions (all versions).

I mentioned about this vulnerability at my site

Best wishes & regards,
Administrator of Websecurity web site 

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2015 AOH