StatsPlus HTTP Header HTML Injection...

- AV AC AU C I A
发布: 2002-07-25
修订: 2025-04-13

StatsPlus is prone to HTML injection attacks. StatsPlus logs information about incoming requests to monitored webpages. HTTP headers such as the HTTP_USER_AGENT and HTTP_REFERER are logged by the software. StatsPlus does not sufficiently sanitize HTML when logging these fields. An attacker may create false HTTP_USER_AGENT and HTTP_REFERER headers which contain arbitrary HTML and script code and it will be stored on the statistics page.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息