Hi im an admin of a forum and i scan my forum with Acunetix and i find 2 xss vulnérability:
-forum/admin/index.php/>"><ScRiPt>alert(574951540479)</ScRiPt>
-net:80/forum/admin/index.php/%22%3E%3Cscript%3Ealert(427441417062)%3C/script%3E%3Ctd%20class=%22p
it say i can do this alert and i try and it work ...... and i try to use an cookie stealer insted of the alert and it send nothing. I know my cookie stealer work cause i already try it in somthing else. am i protected or someone can still cause some trouble? how do i correct it?



