Liferay Enterprise Portal multiple XSS

看板Bugtraq作者時間18年前 (2007/11/28 05:28), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Vendor Site: Liferay.net Version affected: Liferay Enterprise Portal 4.3.1 Demo:http://www.liferay.net/c/portal/login?tabs1=forgot-password Class: Input Validation Error Overview: Liferay fails to sufficiently sanitize user-supplied input data in "email address" text box by pressing the "Send New Password" button. Examples: 1."><script>alert('xss')</script> 2.<html><b>XSS</b></font></html> 3."><iframe> Discovered by: Joshua Morin
文章代碼(AID): #17J8m500 (Bugtraq)