<<< Date Index >>>     <<< Thread Index >>>

PHP Invoice 2.2 (Billing and client Management) home.php Xss vuln.



##################################################
description :
-------------
PHP Invoice designed to automate your entire account, order, billing, ticket 
system needs. From displaying your sales content, to ordering, PHP Invoice will 
handle all your billing and authentication requirements with speed and ease.
No Matter Webmaster, Web Designer, Business Owner, Web Hosting Company or even 
Developer, All you need is PHP Invoice.

venedor :
---------
http://www.phpinvoice.com

Exploite :
----------
http://www.example.com/[path]/home.php?msg=Successfully%20updated&alert=[xss]

This may allow an attacker to steal cookie-based authentication credentials .

----------------------------
Discoverd by :
--------------
meto5757
----------------------------
Greets :
--------
Mesho & Basiony , KaRim (koko) , all my friends .
----------------------------