Message Foundry Multiple Vulnerabilities...

- AV AC AU C I A
发布: 2003-07-17
修订: 2025-04-13

Message Foundry is reportedly prone to multiple vulnerabilities. An HTML injection vulnerability was reported that can be exploited by submitting a value for the "NAME" input field that contains HTML and script code. This could permit execution of hostile HTML and script code in the security context of the site hosting the software. The software is also reported to store the administrative password in plaintext in the MF.ini file. An additional issue is reported that may permit an attacker to change another user's password if they are in the say public or private area of an affected site.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息