Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Packeteer Products File Listing XSS |
|---|---|
| Date: | 24 Feb 2008 21:48:43 -0000 |
Packeteer Products File Listing XSS Product: Packeteer PacketShaper http://www.packeteer.com/products/packetshaper/ Packeteer PolicyCenter http://www.packeteer.com/products/packetshaper/policycenter.cfm The web management interface of several Packeteer products contains a cross-site scripting vulnerability in the file listing function. Parameter FILELIST, specified in an arbitrary page request, is not sufficiently sanitized before it gets embedded in the HTML output of the Error Report page. (The parameter value is limited to 64 characters.) Example: https://(target)/whatever.htm?FILELIST=%3C/script%3E%3Cbody+onLoad=alert(%26quot%3BXSS%26quot%3B)%3E%3Cscript%3E The vulnerability has been identified in version 8.2.2. However, other versions may be also affected. Solution: Do not stay logged into the Packeteer web management interface while browsing other web sites. Found by: nnposter
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Alkacon OpenCms tree_files.jsp resource XSS, nnposter |
|---|---|
| Next by Date: | Php Nuke "Sell" module SQL Injection ("cid"), no-reply |
| Previous by Thread: | Alkacon OpenCms tree_files.jsp resource XSS, nnposter |
| Next by Thread: | Php Nuke "Sell" module SQL Injection ("cid"), no-reply |
| Indexes: | [Date] [Thread] [Top] [All Lists] |