exploit-db-mirror/exploits/linux/remote/22601.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

7 lines
No EOL
714 B
Text

source: https://www.securityfocus.com/bid/7596/info
Inktomi Traffic Server is prone to a cross-site scripting vulnerability. This is due to insufficient sanitization of input passed to the proxy, which will be echoed back in error pages under some circumstances. A malicious attacker could exploit this issue by creating a link which contains hostile HTML and script code and then enticing users of the proxy to visit the link. When the link is visited via the proxy, attacker-supplied script may be interpreted in the user's browser.
Exploitation could permit HTML and script code to access properties of the domain that is requested through the proxy.
http://<spoofed_domain>:443/</em><script>alert()</script>