RemotelyAnywhere Default.HTML Logout Message Injection Weakness

The following proof of concept has been supplied:

https://www.example.com:2000/default.html?logout=asdf&reason=Please%20set%20your%20password%20to%20ABC123%20after%20login


 

Privacy Statement
Copyright 2010, SecurityFocus