## FULL DISCLOSURE
#Date : 27/Jan/2016
“invID, login, UserName, DayFrom, MonthFrom, YearFrom, DayTo, MonthTo, YearTo, usage” parameters are not sanitized that leads to Reflected XSS.
Send following Post request: (unauthenticated)
txtLogin=xss&txtLoginPass=xss&Submit=Login&invID=”/><img src=x onerror=alert(1)>”&recID=
Send following Get request: (authenticated)
This version is already patched according to Vendor.
Vulnerability Disclosure Timeline:
→ January 18, 2015 – Bug discovered, initial report to Vendor
→ January 19, 2015 – Vendor acknowledged, version already patched (reported server not updated)
→ January 19, 2015 – Vendor asked for the affected server IP.
→ January 20, 2015 – Affected server IP, reported.
→ January 25, 2015 – Affected Server Patched.
Permission is hereby granted for the redistribution of this advisory,
provided that it is not altered except by reformatting it, and that due
credit is given. Permission is explicitly given for insertion in
vulnerability databases and similar, provided that due credit is given to
The author is not responsible for any misuse of the information contained
herein and prohibits any malicious use of all security related information
or exploits by the author or elsewhere.