JSPMySQL Administrador Cross-Site Scripting Vulnerability (CVE-2015-6945)
JSPMySQL Administrador Cross-Site Scripting Vulnerability (CVE-2015-6945)
Release date:
Updated on:
Affected Systems:
JSPMySQL Administrador JSPMySQL Administrador 0.1
Description:
CVE (CAN) ID: CVE-2015-6945
JSPMySQL Administrador is a remote management tool for MySQL Databases on JSP Web servers.
A cross-site scripting vulnerability exists in JSP/MySQL Administrador Web 1. Remote attackers can exploit this vulnerability to inject arbitrary Web scripts or HTML through the bd parameters of sys/listaBD2.jsp.
<* Source: hyp3rlinx
Link: http://www.securityfocus.com/archive/1/archive/1/536406/100/0/threaded
*>
Test method:
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Hyp3rlinx () provides the following test methods:
Http: // localhost: 8081/sys/listaBD2.jsp? Bd = % 22/% 3E % 3 Cscript % 3 Ealert % 2
8666% 29% 3C/script % 3E
Suggestion:
Vendor patch:
JSPMySQL Administrador
----------------------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Https://sites.google.com/site/mfpledon/producao-de-software
This article permanently updates the link address: