Tag
#xss
A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
This archive holds a whitepaper called Introduction to Web Pentesting. It provides basic configuration for Burpsuite Proxy along with basic exploitation cross site scripting, SQL injection, cross site request forgery, and open redirects. Two copies of the whitepaper are included. One is in English and one is in Bulgarian.
Perch CMS version 3.2 suffers from a persistent cross site scripting vulnerability.
Joomla JLex GuestBook extension version 1.6.4 suffers from a cross site scripting vulnerability.
CRM Education Akademik version 9.0 suffers from a directory traversal vulnerability.
CREDITS PREVICINI CMS version 1.02 suffers from a cross site scripting vulnerability.
Coupons CMS version 4.00 suffers from an open redirection vulnerability.
Verint Engagement Management 15.3 Update 2023R2 is vulnerable to HTML injection via the user data form in the live chat.
A XSS vulnerability exists in the Xiaomi cloud service Application product. The vulnerability is caused by Webview's whitelist checking function allowing javascript protocol to be loaded and can be exploited by attackers to steal Xiaomi cloud service account's cookies.
Given the privileged position these devices occupy on the networks they serve, they are prime targets for attackers, so their security posture is of paramount importance.