about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Sun Solaris AnswerBook2 Multiple Cross-Site Scripting Vulnerabilities


Title Sun Solaris AnswerBook2 Multiple Cross-Site Scripting Vulnerabilities
Published 2005-03-07-12:00AM
Updated 2005-03-28-08:21PM
Class Input Validation Error
CVE   CAN-2005-0548 CAN-2005-0549
Remote  Yes
Local  No
Credit  Discovery is credited to Thomas Liam Romanis.
Vulnerable  Sun AnswerBook2 1.4.4
Sun AnswerBook2 1.4.3
Sun AnswerBook2 1.4.2
Sun Solaris 2.3
Sun Solaris 2.4
Sun Solaris 2.4 _x86
Sun Solaris 2.5
Sun Solaris 2.5 _x86
Sun Solaris 2.5.1
Sun Solaris 2.5.1 _ppc
Sun Solaris 2.5.1 _x86
Sun Solaris 2.6
Sun Solaris 2.6 _x86
Sun Solaris 7.0
Sun Solaris 7.0 _x86
Sun Solaris 8.0
Sun Solaris 8.0 _x86
Sun AnswerBook2 1.4.1
Sun Solaris 2.3
Sun Solaris 2.4
Sun Solaris 2.4 _x86
Sun Solaris 2.5
Sun Solaris 2.5 _x86
Sun Solaris 2.5.1
Sun Solaris 2.5.1 _ppc
Sun Solaris 2.5.1 _x86
Sun Solaris 2.6
Sun Solaris 2.6 _x86
Sun Solaris 7.0
Sun Solaris 7.0 _x86
Sun Solaris 8.0
Sun Solaris 8.0 _x86
Sun AnswerBook2 1.4
Sun Solaris 2.3
Sun Solaris 2.4
Sun Solaris 2.4 _x86
Sun Solaris 2.5
Sun Solaris 2.5 _x86
Sun Solaris 2.5.1
Sun Solaris 2.5.1 _ppc
Sun Solaris 2.5.1 _x86
Sun Solaris 2.6
Sun Solaris 2.6 _x86
Sun Solaris 7.0
Sun Solaris 7.0 _x86
Sun Solaris 8.0
Sun Solaris 8.0 _x86
Sun AnswerBook2 1.3
Sun Solaris 2.3
Sun Solaris 2.4
Sun Solaris 2.4 _x86
Sun Solaris 2.5
Sun Solaris 2.5 _x86
Sun Solaris 2.5.1
Sun Solaris 2.5.1 _ppc
Sun Solaris 2.5.1 _x86
Sun Solaris 2.6
Sun Solaris 2.6 _x86
Sun Solaris 7.0
Sun Solaris 7.0 _x86
Sun Solaris 8.0
Sun Solaris 8.0 _x86
Sun AnswerBook2 1.2
Not Vulnerable  
Code   An exploit is not required.

The following proof of concepts are available:

For the cross-site scripting issue in the Answerbook2 search function:
http://www.example.com/ab2/Help_C/@Ab2HelpSearch?scope=HELP&DwebQuery=%3Cscript%3Ealert%28%22hello%22%
29%3C%2Fscript%3E&Search=+Search+

For the admin interface 'View Log Files' function:
http://www.example.com/ab2/@Ab2Admin?command=view_access
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 04:31:36 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
serv-u ftp www.sex.pk Wiclear Adult xxx. mwchat%252 WWW.sexwor glftpd mastercard www.js008. www.shange 200 /compo docmint bbs.1010px sexpoto maxcpm.inf mambo+Remo www.80845. P...ic.com maxcpm.inf www.vuonon t33t default CMS is Fre hijab arab the used modules/co ass tamil wome phpBB 2.0. www.trisha mambo Remo t865t www.colleg cerita sex WWW.BBC+UR www.colleg lo770l cerita sex Hollywoods madteenies tamil kira Laura Ange jaascois free enmal www.jibaiz sexphotes bollybood. www.tamil+ nangidiyam rpc 2003