9 lines
No EOL
732 B
Text
9 lines
No EOL
732 B
Text
source: https://www.securityfocus.com/bid/9846/info
|
|
|
|
It has been reported that GNU MyProxy may be prone to a cross-site scripting vulnerability that may allow a remote attacker to execute HTML or script code in a user's browser. The issue presents itself due to insufficient sanitization of user-supplied data.
|
|
|
|
Due to the possibility of attacker-specified HTML and script code being rendered in a victim's browser, it is possible to steal cookie-based authentication credentials from that user. Other attacks are possible as well.
|
|
|
|
GNU MyProxy version 20030629 has been reported to be affected by this issue, however, it is possible that other versions are vulnerable as well.
|
|
|
|
http://www.example.com/<script>alert("Test")</script> |