Advertisement






PassMasterFlex (and PassMasterFlex+) XSS injection

CVE Category Price Severity
N/A CWE-79 N/A High
Author Risk Exploitation Type Date
Unknown High Remote 2006-05-23
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2006050076

Below is a copy:

PassMasterFlex (and PassMasterFlex+) XSS injection

Discovered by: Nomenumbra
Date: 5/4/2006
impact:moderate (privilege escalation,possible defacement)

PassMasterFlex(+) is a database-driven multiple login that utilizes cookies for authentication.
PassMasterFlex+ was written not only to provide an alternative to the Apache login but in 
response to numerous requests to have multiple users.

PMF doesn't filter any data in the user's profiles, thus allowing them to embed any XSS code there
to elevate their privileges.
Also upon failed login attempt, data gets written to the "hack-log" but without filtering. It is
possible to embed XSS in a custom user-agent to obtain cookies.

Nomenumbra/[0x4F4C]


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum