Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v9 - Exploits Update (Thu Sep 10 2009)

VirtualMin Dom Parameter Cross Site Scripting Exploit

Exploits/Cross Site Scripting (XSS)/Known Vulnerabilities  []




• Thu Sep 10 2009
Input passed to the "dom" parameter in left.cgi and via the URL to virtual-server/link.cgi is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Exploits Vulnerabiltiy: NOCVE-9999-39439



< Back to Product Updates