Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

  [Aria-Security Team] social-networkin SQL Injection

  NuclearBB Alpha 2 Remote File Inclusion

  Husrev Forums v2.0.1:PoWerBoard Sql

  Proxy Anket v3.0.1 Sql injection Vulnerable

From:r0t <krustevs_(at)_googlemail.com>
Date:11 сентября 2007 г.
Subject:DirectAdmin <= v1.30.2 XSS vuln.

DirectAdmin <= v1.30.2 XSS vuln.
###############################################
Vuln. discovered by : r0t
Date: 10 September 2007
vendor:http://www.directadmin.com/
orginal advisory:
http://pridels-team.blogspot.com/2007/09/directadmin-v1302-xss-vuln.html
affected versions:v1.30.2 and previous
###############################################

DirectAdmin contains a flaw that allows a remote Cross-Site Scripting
attacks.Input passed to the "user" parameter in "CMD_BANDWIDTH_BREAKDOWN"
isn't properly sanitised before being returned to the user.
This can be exploited to execute arbitrary HTML and script code in a user's
browser session in context of an affected site.

###############################################
Solution:
Filter malicious characters and character sequences in a web proxy.
###############################################

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server