BizDir 5.10 Cross Site Scripting

2010-12-12 / 2010-12-13
Risk: Low
Local: No
Remote: Yes
CWE: CWE-79 advisory: Non-persistent XSS in BizDir Summary: Details: -----------Summary----------- eVuln ID: EV0158 Software: BizDir Vendor: LEXIPIXEL Version: v.05.10 Critical Level: low Type: Cross Site Scripting Status: Unpatched. No reply from developer(s) PoC: Not available Solution: Available Discovered by: Aliaksandr Hartsuyeu ( ) --------Description-------- It is possible to inject xss code into f_srch parameter in bizdir.cgi script. Parameter f_srch is not properly sanitized before being used in HTML code. --------PoC/Exploit-------- Non-persistent XSS Example. XSS example: http://website/cgi-bin/bizdir/bizdir.cgi?f_mode=srch& f_srch=<XSS inj>&f_srch_mode=SOME&f_start_at=1 ---------Solution---------- Available: update to latest version. ----------Credit----------- Vulnerability discovered by Aliaksandr Hartsuyeu - "FTP infection" article

Vote for this issue:


Thanks for you vote!


Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.

(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024,


Back to Top