|
Brought to you by:
Suppliers of:
|
|
|
| |
| The APC Switch RACK PDU web administration login page is prone to a cross-site scripting vulnerability because the application fails to sufficiently sanitize user-supplied input. |
| |
Credit:
The information has been provided by Jamal Pecou.
|
| |
Vulnerable Systems:
* APC Switch RACK PDU version 3.7.0 and prior
The script "login1" located in the Forms directory fails to properly sanitize user input data in the login_username field
http://<PDU IP>/Forms/login1?login_username=<ScRiPt>alert('hello');</ScRiPt>
Disclosure Timeline:
Jun 17th 2009 - Vulnerability Discovered
Jun 18th 2009 - Contacted Vendor
Jun 21st 2009 - APC Creates a ticket and enters finding into bug tracking database.
Dec 14th 2009 - APC, no patches released.
--------------------------------------------------------------------------------------------------------------------------------
Vulnerabilities like this exist in many sites. Find out how to eliminate XSS.
*
|
|
|
|
|