|
Brought to you by:
Suppliers of:
|
|
|
| |
| Content Server is "a web content management from divine". A Cross Site Scripting in this product allows injection of hostile HTML/script into the error page. |
| |
Credit:
The information has been provided by Valgasu.
|
| |
Example:
By using the following URL: http://vulsite/servlet/ContentServer?pagename=< body%20onload=alert(document.cookie);> an attacker can capture the user's cookie.
|
|
|
|
|