RETIRED: DirectAdmin 'CMD_DOMAIN' Cross-Site Scripting Vulnerability

DirectAdmin is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.

An attacker can leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

DirectAdmin 1.403 is vulnerable; other versions may also be affected.

Note: This BID is being retired as a duplicate of BID 52845 (JBMC Software DirectAdmin 'domain' Parameter Cross Site Scripting Vulnerability).


 

Privacy Statement
Copyright 2010, SecurityFocus