PHPay Cross Site Scripting Vulnerability...

- AV AC AU C I A
发布: 2003-04-09
修订: 2025-04-13

It has been reported that user-supplied input to phPay is not sufficiently sanitized. This lack of sanitization provides an opportunity for an attacker to launch cross-site scripting attacks. It is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of a legitimate user. Any attacker-supplied code will be executed within the context of the website running phPay. While this vulnerability has been reported to affect phPay version 2.02, previous versions may also be affected.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息