ERNW-SA.Newtelligence.txt...

- AV AC AU C I A
发布: 2004-09-09
修订: 2025-04-13

A cross site scripting vulnerability in DasBlog's Event and Activity Viewer allows to inject and execute code on the client's machine. This allows an attacker to transfer the ASP.NET authentication cookie to a server of his choice. The attacker can use this cookie to log on to DasBlog and modify blog entries and configuration settings.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息