NetWin DBabble 2.5 i - Cross-Site Scripting



EKU-ID: 28608 CVE: OSVDB-2551 OSVDB-ID:
Author: dr_insane Published: 2003-09-16 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/8637/info

A cross-site scripting problem has been reported in NetWin DBabble. This could make it possible for an attacker to potentially execute code in the security context of a site using the vulnerable software. This could be exploited by enticing a user to follow a malicious link to a site hosting the software.

http://www.example.com/dbabble?cmd="><evil_script>