[VIM] Source VERIFY of CityPost LNKX msg XSS

Steven M. Christey coley at mitre.org
Fri Jan 27 17:09:09 EST 2006


Ref: SECTRACK:103752

Using the file downloaded from:
http://tech.tailoredweb.com/download.php?f=/link-exchange-52/link-exchange-52.zip

It's not clear what the actual version number is, though.

from message.php:

[1] <? include "_header.inc"; ?>

there's no PHP in this file.

>    <?=$_REQUEST["msg"]?>

bingo.

- Steve


More information about the VIM mailing list