CORE IMPACT v9 - Exploits Update (Thu Sep 10 2009)
VirtualMin Dom Parameter Cross Site Scripting Exploit
Exploits/Cross Site Scripting (XSS)/Known Vulnerabilities []
Thu Sep 10 2009
Input passed to the "dom" parameter in left.cgi and via the URL to virtual-server/link.cgi is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Exploits Vulnerabiltiy: NOCVE-9999-39439











