|
Assetman <= 2.4a XSS=0D
=0D
Discovered by: Nomenumbra=0D
Date: 23/5/2006=0D
impact:moderate (privilege escalation,possible defacement)=0D
=0D
Assetman doesn't filter any of it's input, allowing users=0D
to inject arbitrary HTML or javascript code.=0D
=0D
Nomenumbra