|
|
| |
| A security vulnerability in Hosting.com's web based email engine, allows attackers to cause the program to insert HTML and JavaScript into user displayed pages. This would allow an attacker to utilize a Cross Site Scripting attack against the user. |
| |
Credit:
The information has been provided by E M.
|
| |
Most variables passed to the webmail script used by hosting.com (formerly CTSNet) can be used to execute scripts with local server context.
Exploit:
(NOTE, the 'I' of SCRIPT has been replaced with an '!')
http://webmail.cts.com/webmail.cgi?_ID=<SCR!PT>alert("All%20Your%20Webmail%20is%20Belong%20to%20Us");</SCRIPT>
|
|
|
|
|
|
|
|