---------------------------------------------------------- ---- Team priestmasters PHP Counter 7.2 XSS Advisorie ---- ---------------------------------------------------------- PHP Counter Vendor: http://www.ekstreme.com/phplabs/phpcounter.php PHP Counter 7.2 does not filter "<>" tags in EpochPrefix parameter. Cross site scripting and HTML injection is possible. Exploitation: http://www.yourwebsite.org/CounterDirectory/index.php?Plugin=All%20Hits&EpochPrefix="> The injected script is called multiple times. XSS is hard to do because ' and " are filtered. greets, priestmaster URL: http://www.priestmaster.org Email: priest@priestmaster.org