Bandmin Cross-Site Scripting Vulnerability
BID:7729
Info
Bandmin Cross-Site Scripting Vulnerability
| Bugtraq ID: | 7729 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0416 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery credited to silent needel <[email protected]>. |
| Vulnerable: |
Bandmin Bandmin 1.4 |
| Not Vulnerable: | |
Discussion
Bandmin Cross-Site Scripting Vulnerability
It has been reported that a cross-site scripting vulnerability exists in Bandmin. Because of this, an attacker may be able to execute script code or HTML in the context of the site hosting Bandmin by enticing a web user to follow a malicious link.
It has been reported that a cross-site scripting vulnerability exists in Bandmin. Because of this, an attacker may be able to execute script code or HTML in the context of the site hosting Bandmin by enticing a web user to follow a malicious link.
Exploit / POC
Bandmin Cross-Site Scripting Vulnerability
No exploit is required for this vulnerability.
The following proofs of concept were made available by silent needel <[email protected]>:
http://www.example.com/bandwidth/index.cgi?action=showmonth&year=[FIRST SCRIPT]&month=[SECOND SCRIPT]
http://www.example.com/bandwidth/index.cgi?action=showhost&month=May&year=2003&host=[THIRD SCRIPT]
No exploit is required for this vulnerability.
The following proofs of concept were made available by silent needel <[email protected]>:
http://www.example.com/bandwidth/index.cgi?action=showmonth&year=[FIRST SCRIPT]&month=[SECOND SCRIPT]
http://www.example.com/bandwidth/index.cgi?action=showhost&month=May&year=2003&host=[THIRD SCRIPT]