Thread-ITSQL HTML Injection...

- AV AC AU C I A
发布: 2003-09-24
修订: 2025-04-13

Thread-ITSQL is prone to a number of HTML injection issues. In particular, when users submit messages, input supplied via the Topic Title, Name and Message form fields will not be adequately sanitized of HTML and script code. Remote attackers could exploit this issue to inject hostile HTML and script into the site hosting the software, which could be rendered in the browsers of users visiting the site.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息