12.07.2015 Views

APPLICATION PENETRATION TEST SUPER VEDA

APPLICATION PENETRATION TEST SUPER VEDA

APPLICATION PENETRATION TEST SUPER VEDA

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Application Penetration Test for Super Veda- Sample Report -5.7 CROSS-SITE SCRIPTINGSeverity: MediumAn attacker can take advantage of numerous input fields in the applicationin order to mislead an innocent customer entering the site into giving awayinformation, or as a tunnel for the attacker for future purchases on behalfof the first. Input fields include the comments area, the search page, andthe new user signup form.The first cross site scripting attack is based on a malicious userembedding malicious code (in the form of Javascript or VBScript) in thesearch field of the search.asp page. This allows an attacker to send a mailto any user asking him to view a list of search results. If the innocent userwould surf to this linked page, where the malicious code is injected by theattacker he would have a response script sent to him. This can result inthe user’s session cookie sent to the attacker for instance, which willenable the attacker to act on the user’s behalf without his knowledge.Appendix G - Cross-site Scripting demonstrates this problem.ImpervaPage30 of73

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!