Dell KACE K1000 Systems Management Appliance 'LABEL_ID' Parameter Cross Site Scripting Vulnerability
BID:65333
Info
Dell KACE K1000 Systems Management Appliance 'LABEL_ID' Parameter Cross Site Scripting Vulnerability
| Bugtraq ID: | 65333 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0330 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2014 12:00AM |
| Updated: | Feb 04 2014 12:00AM |
| Credit: | William Costa. |
| Vulnerable: | |
| Not Vulnerable: | |
Exploit / POC
Dell KACE K1000 Systems Management Appliance 'LABEL_ID' Parameter Cross Site Scripting Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
Following example URL is available.
http://www.example.com/adminui/user_list.php?SEARCH_SELECTION=&LABEL_ID=[XSS]
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
Following example URL is available.
http://www.example.com/adminui/user_list.php?SEARCH_SELECTION=&LABEL_ID=[XSS]