Liferay Enterprise Portal multiple XSS Nov 27 2007 08:20PM
morin josh gmail com
Vendor Site: Liferay.net

Version affected: Liferay Enterprise Portal 4.3.1

Demo:http://www.liferay.net/c/portal/login?tabs1=forgot-password

Class: Input Validation Error

Overview: Liferay fails to sufficiently sanitize user-supplied input data in "email address" text box by pressing the "Send New Password" button.

Examples:

1."><script>alert('xss')</script>

2.<html><b>XSS</b></font></html>

3."><iframe>

Discovered by: Joshua Morin

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus