Description - XSS Vulnerability in Pixelpost Photoblog

Cross Site Scripting found in Pixelpost Photoblog script.

Exploit
Available
Solution
Not available - check vendor's website

Vulnerable script: index.php

Most of user-defined variables isn't properly sanitized. This can be used to post arbitrary html or script code. This code will be executed when administrator will open "comments" menu in admin CP.

Cookie-based authentication is threatened.

Administrator has an ability to upload arbitrary files.

System access is possible.

Order Source Code Analysis made by eVuln team

Protect against attacks by source code test of a website made by eVuln team.The task will be done by experts in website security.