Exploit Inktomi Traffic Server 4.0/5.x - Cross-Site Scripting

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
22601
Проверка EDB
  1. Пройдено
Автор
HUGO VAZQUEZ
Тип уязвимости
REMOTE
Платформа
LINUX
CVE
N/A
Дата публикации
2003-05-14
Код:
source: https://www.securityfocus.com/bid/7596/info

Inktomi Traffic Server is prone to a cross-site scripting vulnerability. This is due to insufficient sanitization of input passed to the proxy, which will be echoed back in error pages under some circumstances. A malicious attacker could exploit this issue by creating a link which contains hostile HTML and script code and then enticing users of the proxy to visit the link. When the link is visited via the proxy, attacker-supplied script may be interpreted in the user's browser.

Exploitation could permit HTML and script code to access properties of the domain that is requested through the proxy.

http://<spoofed_domain>:443/</em><script>alert()</script>
 
Источник
www.exploit-db.com

Похожие темы