Selenium Web Server 1.0 - Cross-Site Scripting

Related Vulnerabilities: CVE-2006-6124  
Publish Date: 15 Nov 2006
Author: Greg Linares
                							

                source: http://www.securityfocus.com/bid/21100/info

Biba Selenium Web Server is prone to a cross-site scripting because the application fails to sufficiently sanitize user-supplied input.

An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may lead to other attacks.

http://www.example.com/%3Cscript%3Ealert('CSS_Vulnerable')%3C/script%3E