source: https://www.securityfocus.com/bid/49793/info ServersCheck Monitoring Software is prone to multiple remote input-validation vulnerabilities, including: 1. Multiple HTML-injection vulnerabilities 2. Multiple cross-site scripting vulnerabilities 3. A cross-site request forgery vulnerability 4. Multiple local file-include vulnerabilities 5. A security vulnerability that may allow attackers to send arbitrary SMS messages from the vendor's phone number. An attacker can exploit these issues to execute arbitrary HTML and script code in the context of the browser or the Web server, gain access to sensitive information, send multiple SMS messages, and perform certain administrative tasks. Other attacks are also possible. Code Review: Input Validation Vulnerabilities (Persistent) http://www.example.com/userslist.html?
Benutzername Zugriffsrechte Löschen
>"&'>>" ">
"