SiteCore XML Control Script Insertion

看板Bugtraq作者時間12年前 (2014/01/29 18:32), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Hey All, Sitecores 昼pecial way鐠of displaying XML Controls directly allows for a Cross Site Scripting Attack 阠more can be achieved with these XML Controls and will be documented in another vulnerability report http://target/?xmlcontrol=body%20onload=alert(123) http://target/?xmlcontrol=iframe%20src=https://www.google.com/images/srpr/logo11w.png
More information can be found at http://www.securatary.com/vulnerabilities - Also listed is a useful text file for use with Burp when auditing SiteCore.
文章代碼(AID): #1IwDYYyf (Bugtraq)