A proof of concept to exploit the reflected XSS vulnerability in the oVirt web interface (RedHat). In this PoC a VM in the oVirt IaaS environment is to be started via the victim's browser session. JS code has been kept simple due to the rush.# CVE-2016-3113 (PoC)
A proof of concept to exploit the reflected XSS vulnerability in the oVirt web interface (RedHat). In this PoC a VM in the oVirt IaaS environment is to be started via the victim's browser session. JS code has been kept simple due to the rush.
More Info here:
https://www.itskritis.de/_uploads/jk17/Students___Freigabeversion/DURMAZ___Praesentation.pdf (slides in german language)
https://access.redhat.com/security/cve/cve-2016-3113
https://bugzilla.redhat.com/show_bug.cgi?format=multiple&id=1326598
[4.0K] /data/pocs/64dc05cff0baa64ec54c0d68af0f44428025c161
├── [ 16K] BigInteger.min.js
├── [8.2K] ovirtXSSExploitVmStarten.js
├── [ 535] README.md
└── [ 627] runExploitSelfsubmittingForm.html
0 directories, 4 files