Lilikoi Software Ceilidh Cross Site...

- AV AC AU C I A
发布: 2003-03-27
修订: 2025-04-13

Ceilidh does not adequately filter some HTML code thus making it prone to cross-site scripting attacks. It is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user. An attacker can exploit this vulnerability by manipulating URI parameters for the testcgi.exe script. This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software. The attacker may hijack the session of the legitimate by using cookie-based authentication credentials.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息