Bugtraq mailing list archives
ContentDM Search.php XSS Vulnerability
From: Monkeyboy9997 () hotmail com
Date: 4 Aug 2007 10:55:13 -0000
ContentDM has a XSS vulnerability. Many .gov sites run this software. CDM fails to block special charachters etc so by searching for <script>alert('XSS');</script> We can make a popup saying XSS. An attacker could steal cookies, redirect the page etc. Found by Me(Rhys Phillips) Date found: 3rd August 2007 Date Released: 3rd August 2007 Vendor has been contacted.
Current thread:
- ContentDM Search.php XSS Vulnerability Monkeyboy9997 (Aug 04)