Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

AssetMan 'search_inv.php' Multiple Vulnerabilities

An attacker can exploit these issues via a browser. To exploit cross-site scripting and session-fixation issues, the attacker entices an unsuspecting victim to following a malicious URI.

The following example URI is available:

http://www.example.com/assetman/search_inv.php?action=search_all&order_by=%3Cmeta+http-equiv='Set-cookie'+content='=value'%3E&order=DESC+limit+1,1--







 

Privacy Statement
Copyright 2009, SecurityFocus