PHPEcho CMS 20-rc3 (forum) XSS Cookie Stealing / Blind Vulnerability
bug found by Jose Luis Gongora Fernandez (aka) JosS
contact: sys-project[at]hotmailcom
website: wwwhack0wncom/
- download: sourceforgenet/project/showfilesphp?group_id=186100
~ [XSS]
The forum allowed insert javascript code and html code
PoC:
"> ...