BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: JBoss jmx-console CSRF Feb 23 2007 12:21AM
pagvac (unknown pentester gmail com)
Hey dude!

What's the authentication mechanism used by JBoss console? A login
HTML form, or HTTP basic auth? If it's the first one and cookies are
used as session tokens your exploit should work (the web browser will
submit the cookie to the target IP/domain when the evil page is
visited).

Although...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus