lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20070914110757.27817.qmail@securityfocus.com> Date: 14 Sep 2007 11:07:57 -0000 From: root@...icker.it To: bugtraq@...urityfocus.com Subject: new XSS vulnerability in php-stats -tracking.php I found a new xss in php-stats 0.1.9.2 http://phpstats.net/ http://www.example.com/php-stats-path/tracking.php?what=online&ip=[XSS] Stats must have public access for this (difference from whois.php XSS).