Exploit Verity K2 Toolkit 2.20 Query Builder Search Script - Cross-Site Scripting

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
22857
Проверка EDB
  1. Пройдено
Автор
SSR TEAM
Тип уязвимости
WEBAPPS
Платформа
JSP
CVE
N/A
Дата публикации
2003-07-02
Код:
source: https://www.securityfocus.com/bid/8074/info

It has been reported that the K2 Toolkit does not sufficiently sanitize input by users. Because of this, it may be possible for an attacker to launch an attack that results in the execution of hostile HTML or script code in the browsers of users that have loaded a malicious link created by the attacker.

http://www.example.com/[search].jsp?[query]=><img src=javascript:alert(document.cookie)>
 
Источник
www.exploit-db.com

Похожие темы