NetWin DBabble 2.5 i - Cross-Site Scripting

EDB-ID:

23153

CVE:





Platform:

CGI

Date:

2003-09-16


Become a Certified Penetration Tester

Enroll in Penetration Testing with Kali Linux and pass the exam to become an Offensive Security Certified Professional (OSCP). All new content for 2020.

GET CERTIFIED

source: https://www.securityfocus.com/bid/8637/info

A cross-site scripting problem has been reported in NetWin DBabble. This could make it possible for an attacker to potentially execute code in the security context of a site using the vulnerable software. This could be exploited by enticing a user to follow a malicious link to a site hosting the software. 

http://www.example.com/dbabble?cmd="><evil_script>