.. / CVE-2008-6465

Exploit for Parallels H-Sphere 3.0.0 P9/3.1 P1 - Cross-Site Scripting (CVE-2008-6465)

Description:

Parallels H-Sphere 3.0.0 P9 and 3.1 P1 contains multiple cross-site scripting vulnerabilities in login.php in webshell4. An attacker can inject arbitrary web script or HTML via the err, errorcode, and login parameters, thus allowing theft of cookie-based authentication credentials and launch of other attacks.

Nuclei Template

View the template here CVE-2008-6465.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2008/CVE-2008-6465.yaml
Copy

References:

https://exchange.xforce.ibmcloud.com/vulnerabilities/45254
http://www.xssing.com/index.php?x=3&y=65
https://github.com/ARPSyndicate/kenzer-templates
https://exchange.xforce.ibmcloud.com/vulnerabilities/45252
https://nvd.nist.gov/vuln/detail/CVE-2008-6465