LiteSpeed 4.1.11 Cross Site Scripting

2012.03.20
Credit: K1P0D
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

Hey, so i decided to open this blog with with a post about a vulnerability I?ve found quite some time ago in LiteSpeed HTTP server Basically a simple reflected XSS(Cross Site Scripting) in the administrator panel which is another instance of the HTTP server running on port 7080 If an attacker succeed in convincing an administrator with an active session to enter a maliciously crafted link using this vulnerability an attacker may perform malicious act such as creating a new user with administrator privileges or in other words ? Pwnage. To reproduce: http://lightspeed-server:7080/service/graph_html.php?gtitle=VHOSTa%3Cscript%3Ealert%28document.cookie%29%3C/script%3E 14/3/2012 ? Vendor was notified anyway nothing too technical/interesting for now.


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top