Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Cerberus Helpdesk vulnerable to XSS Jan 30 2006 11:42PM
preben watchcom no
Inputs in the Cerberus Helpdesk is not properly sanitized, and XSS is possible in a lot of the systems input fields and url parameters.

You can add XSS that will hit every user of the system, and even simple scripting tags like <script>alert(?f?)</script> is allowed

PoC: http://www.SITE.example/tt...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus