title,url - Non-persistent XSS in Social Share
- title,url - Non-persistent XSS in Social Share
- Last Update
- n/a n/a
- Risk Level
- Cross Site Scripting
- Unpatched. Vendor notified. No reply from developer(s).
- Vulnerable Software
- Social Share (http://sourceforge.net/projects/socialshare/)
- Not available
- Discovered by
- Aliaksandr Hartsuyeu (eVuln.com)
Cross Site Scripting found in Social Share (http://sourceforge.net/projects/socialshare/) script.
- Non-persistent XSS
- It is possible to inject xss code into title and url parameters in save.php script.
Parameters title, url are not properly sanitized before being used in HTML code.
Non-persistent XSS Example.
XSS example1: http://website/socialshare/save.php?title=<XSS>
XSS example2: http://website/socialshare/save.php?url="><XSS>
Solution for "title,url - Non-persistent XSS in Social Share" is not available. Check vendor's website for updates.
Order Source Code Analysis
Protect against attacks by source code audit of a website or web application made by our team.The order will be done by experts in website security.