Bugtraq mailing list archives

Assetman <= 2.4a XSS


From: zerogue () gmail com
Date: 23 May 2006 17:54:36 -0000

Assetman <= 2.4a XSS

Discovered by: Nomenumbra
Date: 23/5/2006
impact:moderate (privilege escalation,possible defacement)

Assetman doesn't filter any of it's input, allowing users
to inject arbitrary HTML or javascript code.

Nomenumbra


Current thread: