SurgeLDAP User.CGI Cross-Site Scripting Vulnerability
BID:8407
Info
SurgeLDAP User.CGI Cross-Site Scripting Vulnerability
| Bugtraq ID: | 8407 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2003 12:00AM |
| Updated: | Aug 13 2003 12:00AM |
| Credit: | Discovery is credited to Ziv Kamir. |
| Vulnerable: |
NetWin SurgeLDAP 1.0 d |
| Not Vulnerable: |
NetWin SurgeLDAP 1.0 e |
Discussion
SurgeLDAP User.CGI Cross-Site Scripting Vulnerability
SurgeLDAP is prone to cross-site scripting attacks. Remote attackers may exploit this issue by enticing a user to visiting a malicious link that includes hostile HTML and script code. This code may be rendered in the user's browser when the link is visited.
This issue exists in the web server component of SurgeLDAP.
SurgeLDAP is prone to cross-site scripting attacks. Remote attackers may exploit this issue by enticing a user to visiting a malicious link that includes hostile HTML and script code. This code may be rendered in the user's browser when the link is visited.
This issue exists in the web server component of SurgeLDAP.
References
SurgeLDAP User.CGI Cross-Site Scripting Vulnerability
References:
References:
- SurgeLDAP Homepage (NetWin)
- SurgeLDAP Update Information Page (NetWin)