ACWeb Cross-Site Scripting Vulnerability
BID:5793
Info
ACWeb Cross-Site Scripting Vulnerability
| Bugtraq ID: | 5793 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2002 12:00AM |
| Updated: | Sep 25 2002 12:00AM |
| Credit: | Discovery of this issue is credited to DownBload <[email protected]>. |
| Vulnerable: |
acWEB acWEB 1.14 acWEB acWEB 1.8 |
| Not Vulnerable: | |
Discussion
ACWeb Cross-Site Scripting Vulnerability
acWEB is prone to cross-site scripting attacks. It is possible to construct a malicious link to the web server which contains arbitrary script code. When the link is visited, the script code will be executed in the web client of the user visiting the link. The code will be executed in the context of the webserver.
acWEB is prone to cross-site scripting attacks. It is possible to construct a malicious link to the web server which contains arbitrary script code. When the link is visited, the script code will be executed in the web client of the user visiting the link. The code will be executed in the context of the webserver.
Exploit / POC
ACWeb Cross-Site Scripting Vulnerability
The following example was submitted:
http://www.victim.com/%db<script>alert('test');</script>/
The following example was submitted:
http://www.victim.com/%db<script>alert('test');</script>/
Solution / Fix
ACWeb Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.