批踢踢實業坊
›
看板
Bugtraq
關於我們
聯絡資訊
返回看板
發信人
root@hanicker.it,
看板
Bugtraq
標 題
new XSS vulnerability in php-stats -tracking.php
發信站
NCTU CSIE FreeBSD Server (Sat Sep 15 09:17:32 2007)
轉信站
ptt!FreeBSD.csie.NCTU!not-for-mail
I found a new xss in php-stats 0.1.9.2
http://phpstats.net/
http://www.example.com/php-stats-path/tracking.php?what=online&ip=[XSS]
Stats must have public access for this (difference from whois.php XSS).