DirectAdmin 'CMD_DB_VIEW' Cross-Site Scripting Vulnerability
BID:38721
Info
DirectAdmin 'CMD_DB_VIEW' Cross-Site Scripting Vulnerability
| Bugtraq ID: | 38721 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2010 12:00AM |
| Updated: | Mar 14 2010 12:00AM |
| Credit: | r0t |
| Vulnerable: |
JBMC Software DirectAdmin 1.33.6 JBMC Software DirectAdmin 1.33.4 JBMC Software DirectAdmin 1.33.3 JBMC Software DirectAdmin 1.30.2 JBMC Software DirectAdmin 1.30.1 JBMC Software DirectAdmin 1.351 JBMC Software DirectAdmin 1.292 |
| Not Vulnerable: | |
Discussion
DirectAdmin 'CMD_DB_VIEW' Cross-Site Scripting Vulnerability
DirectAdmin is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
DirectAdmin 1.351 and prior versions are affected.
DirectAdmin is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
DirectAdmin 1.351 and prior versions are affected.
Exploit / POC
DirectAdmin 'CMD_DB_VIEW' Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URI is available:
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
The following example URI is available:
References
DirectAdmin 'CMD_DB_VIEW' Cross-Site Scripting Vulnerability
References:
References:
- DirectAdmin <= v1.35.1 XSS vuln. (r0t)
- DirectAdmin Homepage (JBMC Software)