PassMasterFlex (and PassMasterFlex+) XSS injection

Discovered by: Nomenumbra

Date: 5/4/2006

impact:moderate (privilege escalation,possible defacement)



PassMasterFlex(+) is a database-driven multiple login that utilizes cookies for 
authentication.

PassMasterFlex+ was written not only to provide an alternative to the Apache 
login but in 

response to numerous requests to have multiple users.


PMF doesn't filter any data in the user's profiles, thus allowing them to embed 
any XSS code there

to elevate their privileges.

Also upon failed login attempt, data gets written to the "hack-log" but without 
filtering. It is

possible to embed XSS in a custom user-agent to obtain cookies.


Nomenumbra/[0x4F4C]

Reply via email to