There are several XSS, a few CSRF etc. on the eures' website.
A sample
http://ec.europa.eu/eures/main.jsp?acro=faq%22%%3C/script%3E%3Cscript%3Ealert(document.cookie);%3C/script%3E%3C&lang=it&catId=489&parentId=0
Even a kid could identify them.
The cookie EURES_SESSIONID can also be (ab)used for other particular things.
You can also impersonate the administrator (maybe I will add an example when they will solve those issues).
Anyway..... I'm still waiting their fix for the pdf/doc generation of the curriculum vitae (about a year have passed since my request for support).
Theorically it's a good service ..... when it works ..... even if I've never used anything except the curriculum generation.
A sample
http://ec.europa.eu/eures/main.jsp?acro=faq%22%%3C/script%3E%3Cscript%3Ealert(document.cookie);%3C/script%3E%3C&lang=it&catId=489&parentId=0
Even a kid could identify them.
The cookie EURES_SESSIONID can also be (ab)used for other particular things.
You can also impersonate the administrator (maybe I will add an example when they will solve those issues).
Anyway..... I'm still waiting their fix for the pdf/doc generation of the curriculum vitae (about a year have passed since my request for support).
Theorically it's a good service ..... when it works ..... even if I've never used anything except the curriculum generation.
Comments
Post a Comment