XSS Injection - Joomla! Forum - community, help and support


hello i'm using 2 extensions 1: hikashop , 2: tabber thing when mixed no matter in .htacess can bypassed using following code:

->"><script>alert(123)</script><"

this not real site can injected this:

http://www.testsite.com/products/category/12->"><script>alert(123)</script><"test-catr.html

joomla version 2.5.8

please, need appreciated. can send real link pm

please follow obvious route, activate 1 of extensions @ time , test confirm 1 is. check doesnt happen when dont have both extensions disabled.
then assuming have latest versions of extensions inform both developer , vel team [ vel@ joomla.org - minus space] vulnerable version name
what trying add htaccess?





Comments

Popular posts from this blog

How to change text Component easybook reloaded *newbee* - Joomla! Forum - community, help and support

After Effect warning: A problem occurred when processing OpenGL commands

Preconditions Failed. - Joomla! Forum - community, help and support