ExpressionEngine-1.4.1.txt...

- AV AC AU C I A
发布: 2006-01-26
修订: 2025-04-13

ExpressionEngine 1.4.1 does not sanatize the HTTP_REFERER variable. This can be used to post HTTP query with fake Referrer value which may contain arbitrary html or script code. This code will be executed when administrator(or any user) will open Referrer Statistics.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息