<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2021-35475_SAS_Environment_Manager_2.5_XSS%E6%BC%8F%E6%B4%9E</id>
	<title>CVE-2021-35475 SAS Environment Manager 2.5 XSS漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2021-35475_SAS_Environment_Manager_2.5_XSS%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2021-35475_SAS_Environment_Manager_2.5_XSS%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-16T20:35:25Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=CVE-2021-35475_SAS_Environment_Manager_2.5_XSS%E6%BC%8F%E6%B4%9E&amp;diff=6017&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;&lt;pre&gt; # Exploit Title: SAS Environment Manager 2.5 - 'name' Stored Cross-Site Scripting (XSS) # Date: 24/06/2021 # Exploit Author: Luqman Hakim Zahari @ Saitamang # Vendor Hom...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2021-35475_SAS_Environment_Manager_2.5_XSS%E6%BC%8F%E6%B4%9E&amp;diff=6017&amp;oldid=prev"/>
		<updated>2021-06-29T01:19:25Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&amp;lt;pre&amp;gt; # Exploit Title: SAS Environment Manager 2.5 - &amp;#039;name&amp;#039; Stored Cross-Site Scripting (XSS) # Date: 24/06/2021 # Exploit Author: Luqman Hakim Zahari @ Saitamang # Vendor Hom...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;br /&gt;
# Exploit Title: SAS Environment Manager 2.5 - 'name' Stored Cross-Site Scripting (XSS)&lt;br /&gt;
# Date: 24/06/2021&lt;br /&gt;
# Exploit Author: Luqman Hakim Zahari @ Saitamang&lt;br /&gt;
# Vendor Homepage: https://support.sas.com/en/software/environment-manager-support.html&lt;br /&gt;
# Version: 2.5&lt;br /&gt;
# Tested on: CentOS 7&lt;br /&gt;
# CVE : CVE-2021-35475&lt;br /&gt;
&lt;br /&gt;
# Description #&lt;br /&gt;
&lt;br /&gt;
SAS® Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Properties.&lt;br /&gt;
&lt;br /&gt;
# Proof of Concept(PoC) # https://github.com/saitamang/CVE-2021-35475/blob/main/README.md&lt;br /&gt;
&lt;br /&gt;
*Steps to Reproduce:*&lt;br /&gt;
&lt;br /&gt;
[1.] Login to your system &amp;gt; On &amp;quot;Resource&amp;quot; tab &amp;gt; &amp;quot;Browse&amp;quot;&amp;quot;&lt;br /&gt;
[2.] Choose a &amp;quot;Platform&amp;quot;&lt;br /&gt;
[3.] Click &amp;quot;Inventory&amp;quot; tab &amp;gt; Under &amp;quot;Servers&amp;quot; tab click &amp;quot;New...&amp;quot;&lt;br /&gt;
[4.] Under &amp;quot;General Properties&amp;quot; tab on &amp;quot;Name&amp;quot; field , enter the payload(below) &amp;gt; Filled up other information and click &amp;quot;Ok&amp;quot; button&lt;br /&gt;
&lt;br /&gt;
payload : &lt;br /&gt;
&lt;br /&gt;
name=XSS&amp;quot;&amp;gt;&amp;lt;marquee onstart=confirm('XSS')&amp;gt;@SAITAMANG&lt;br /&gt;
&lt;br /&gt;
[5.] Successfully saved the payload page will shown&lt;br /&gt;
[6.] Then scroll down to bottom under &amp;quot;Configuration Properties&amp;quot; tab &amp;gt; click &amp;quot;Edit&amp;quot; button&lt;br /&gt;
[7.] Then the payload will be executed&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>