04-15-2012، 12:51 PM
Adobe ColdFusion contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'User-Agent' HTTP header before it is used in an 'id=-' query to a '.cfm' file. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
نحوه استفاده :
توضیحات بیشتر :
http://osvdb.org/70777
نحوه استفاده :
کد:
http://[target]/page.cfm?id=%3Cbody%20onload=alert(document.cookie)%3E
توضیحات بیشتر :
http://osvdb.org/70777
گروه دور همی پارسی کدرز
https://t.me/joinchat/GxVRww3ykLynHFsdCvb7eg
https://t.me/joinchat/GxVRww3ykLynHFsdCvb7eg