Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v10 - Exploits Update (Mon Mar 08 2010)

Zope standard_error_message Cross-Site Scripting Exploit

Exploits/Cross Site Scripting (XSS)/Known Vulnerabilities  []




• Mon Mar 08 2010
Zope is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

Exploits Vulnerabiltiy: NOCVE-9999-41980



< Back to Product Updates