Date: 13 Nov 2007 22:44:36 -0000
From: [email protected]
To: [email protected]Subject: ExoPHPdesk user profile XSS / profile SQL injection
X-Virus-Scanned: antivirus-gw at
ExoPHPdesk user profile XSS / profile SQL injection
You can inject script code into the website area where you create profile. Cookies are in place making an XSS more than possible.' sql here
SQL injection in the profile area is possible if you choose a bad input.