NFlash Useradmin.CGI Script Code...

- AV AC AU C I A
发布: 2003-03-25
修订: 2025-04-13

NFlash has been reported prone to script code injection vulnerabilities. This is due to the lack of sanitization on user-supplied input, used to generate pages with dynamic content. An attacker may inject script code using several form fields or URI parameters of the NFlash user administration page. When another user views one of these pages, the attacker-supplied code will be interpreted in their web browser in the security context of the site hosting the vulnerable software. It may be possible to steal an unsuspecting user's cookie-based authentication credentials, as well as other sensitive information. Other attacks are also possible.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息