Vendor: docuFORM GmbH
Product web page: http://www.docuform.de
Affected version: 6.16a and 5.20
Summary: Unlimited options for production printing and customer solutions.
Desc: The Mercury Web Application suffers from multiple XSS vulnerabilities when
parsing user input thru the GET parameter 'this_url' and the POST parameter 'aa_sfunc'
in f_state.php, f_list.php, f_job.php and f_header.php scripts. Attackers can exploit
these weaknesses to execute arbitrary HTML and script code in a user's browser session.
Tested on: Mercury HTTP and Database Server 6.16
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic