Ticket #674 (reopened Bug report)
XSS on portal
| Reported by: | xkill | Owned by: | RPD |
|---|---|---|---|
| Priority: | high | Milestone: | Gateway 2.0 |
| Component: | Auth server, Authentication, permissions and access control | Version: | Gateway SVN |
| Keywords: | Cc: |
Description
I detected that the portal main page (login page), is vulnerable to XSS at the parameter: wifidog_language
I attach to images with the problem.
Checked using wapiti:
$ wapiti http://wifi.locolandia.net/ Wapiti-1.1.6 (wapiti.sourceforge.net) ................. Attacking urls (GET)... ----------------------- Attacking forms (POST)... ------------------------- Found XSS in http://wifi.locolandia.net/login/ with params = wifidog_language=%3Cscript%3Evar+wapiti_687474703a2f2f776966692e6c6f636f6c616e6469612e6e65742f6c6f67696e2f_77696669646f675f6c616e6775616765%3Dnew+Boolean%28%29%3B%3C%2Fscript%3E coming from http://wifi.locolandia.net/login/ Looking for permanent XSS -------------------------
Attachments
Change History
Note: See
TracTickets for help on using
tickets.

