Menu

#33 Able to inject HTML into URL

open
nobody
None
5
2013-04-12
2013-04-12
Anonymous
No

The ShowDocument and /cgi-bin/ListAllMeetings are vulnerable to HTML injection. For example, the following will generate a popup window on clients:

/DocDB/ShowDocument?docid=3660e4698</title><script>alert(1)</script>5a2aec62a0c

Discussion


Log in to post a comment.