exploit-db-mirror/exploits/multiple/remote/30256.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

9 lines
No EOL
554 B
Text

source: https://www.securityfocus.com/bid/24697/info
Oracle Rapid Install Web Server is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to inject HTML and script code into the browser of an unsuspecting victim. The attacker may then steal cookie-based authentication credentials and launch other attacks.
http://www.example.com:8004/pls/MSBEP004/<script>alert("XSS")</script>
http://www.example.com:8004/pls/<script>alert("XSS")</script>