PostNuke User.PHP UNAME Cross-Site...

- AV AC AU C I A
发布: 2003-06-13
修订: 2025-04-13

The PostNuke 'user.php' script does not sufficiently sanitize data supplied via URI parameters, making it prone to cross-site scripting attacks. This could allow for execution of hostile HTML and script code in the web client of a user who visits a web page that contains the malicious code. Exploitation could allow for theft of cookie-based authentication credentials. Other attacks are also possible.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息