Description
|
|
A new vulnerability was identified in paNews, which may be exploited to conduct Cross Site Scripting attacks. The problem resides in the "comments.php" file when handling the "showpost" parameter, which may be exploited to cause arbitrary scripting code to be executed by the user's browser.
http://www.server.com/comments.php?op=view&newsid=1&showpost="><XSS>
|