- 34,644
- 0
- 18 Дек 2022
- EDB-ID
- 22986
- Проверка EDB
-
- Пройдено
- Автор
- LORENZO HERNANDEZ GARCIA-HIERRO
- Тип уязвимости
- WEBAPPS
- Платформа
- PHP
- CVE
- null
- Дата публикации
- 2003-08-04
Код:
source: https://www.securityfocus.com/bid/8339/info
It is possible to create an authentication or access control page, using Dreamweaver MX PHP Authentication Suite. This script will generate an error page that contains dynamic content when a user fails to authenticate correctly to the site.
A cross-site-scripting vulnerability has been reported to affect PHP authentication functions used in PHP access control pages created with the Macromedia Dreamweaver MX PHP Authentication Suite.
An attacker may exploit this condition to execute arbitrary HTML code in the browser of an unsuspecting user.
http://www.example.com/[PATH]/[LOGIN PAGE].php?[ACCESS DENIED VARIABLE]
="><script>alert('.::\/\|NSRG-18-7|/\/::.');</script>
- Источник
- www.exploit-db.com