Exploit SurgeLDAP 1.0 d - 'User.cgi' Cross-Site Scripting

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
23025
Проверка EDB
  1. Пройдено
Автор
ZIV KAMIR
Тип уязвимости
WEBAPPS
Платформа
CGI
CVE
N/A
Дата публикации
2003-08-13
Код:
source: https://www.securityfocus.com/bid/8407/info

SurgeLDAP is prone to cross-site scripting attacks. Remote attackers may exploit this issue by enticing a user to visiting a malicious link that includes hostile HTML and script code. This code may be rendered in the user's browser when the link is visited.

This issue exists in the web server component of SurgeLDAP.

http://www.example.com:6680/user.cgi?cmd=<script>alert('C.S.S')</script>&utoken=
 
Источник
www.exploit-db.com

Похожие темы