Exploit vqServer 1.9.x - CGI Demo Program Script Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
21411
Проверка EDB
  1. Пройдено
Автор
MATTHEW MURPHY
Тип уязвимости
WEBAPPS
Платформа
CGI
CVE
cve-2002-0731
Дата публикации
2002-04-21
Код:
source: https://www.securityfocus.com/bid/4573/info

vqServer is a HTTP server implemented in Java. vqServer is available on any architecture supporting Java, including Linux and Microsoft Windows.

Reportedly, numerous default CGI scripts included with vqServer suffer from script injection issues, including cross site scripting and the ability to inject script code into cookie content.

http://localhost/cgi/vq/demos/respond.pl<SCRIPT>alert("I%20should%20not%20be%20able%20to%20do%20this!!!")</SCRIPT>
 
Источник
www.exploit-db.com

Похожие темы