Synthetic Reality SymPoll Cross-Site...

- AV AC AU C I A
发布: 2003-11-03
修订: 2025-04-13

It has been reported that Sympoll is prone to a cross-site scripting vulnerability. The issue is reported to exist due insufficient sanitization of user-supplied data through the 'vo' parameter. The problem may allow a remote attacker to execute HTML or script code in the browser of a user following a malicious link created by an attacker. Successful exploitation of this attack may allow an attacker to steal cookie-based authentication information that could be used to launch further attacks. Sympoll version 1.5 is reported to be prone to this issue, however other versions may be affected as well.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息