Yetihost Helm Multiple Cross-Site Scripting Vulnerabilities

To exploit the issue, an attacker must entice an unsuspecting victim into following a malicious URI.

The following proof-of-concept URIs are available:

http://www.example.com/domains.asp?txtDomainName=[XSS]%21&btnSubmit.x=0&btnSubmit.y=0 http//www.example.com/users.asp?SKey=AKU7ACC552W25EA4E8RPBYP67D7EB6RAAJPM8XKA&txtCompanyName=[XSS]&btnSubmit.x=0&btnSubmit.y=0 http://www.example.com/users.asp?txtEmail=[XSS]&btnSubmit.x=0&btnSubmit.y=0 http://www.example.com//users.asp?txtUserAccNum=[XSS]&btnSubmit.x=0&btnSubmit.y=0 http://www.example.com/default.asp?setThemeColour=[XSS]
http://www.example.com/default.asp?setThemeColour=[XSS]
http://www.example.com/domains.asp?txtDomainName=[XSS]%21&btnSubmit.x=0&btnSubmit.y=0#


 

Privacy Statement
Copyright 2010, SecurityFocus