int13h/squert

Parameter not escaped

Opened this issue · 0 comments

Hello, I found a vulnerability that allow inject javascript (XSS) and HTML. This vulnerability is in ip2c.php and the parameter qText

PoC: http://localhost/.inc/ip2c.php?qText="/>HTML CODE