|
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.803109 |
Categoría: | Web application abuses |
Título: | PHP Server Monitor Multiple Stored Cross-Site Scripting Vulnerabilities |
Resumen: | Check if PHP Server Monitor is vulnerable to Cross-Site Scripting |
Descripción: | Description: Overview: This host is installed with PHP Server Monitor and is prone to multiple stored cross-site scripting vulnerabilities. Vulnerability Insight: The flaws are due improper validation of user-supplied input passed via the 'label' and 'name' parameter to 'index.php', that allows attackers to execute arbitrary HTML and script code on the web server. Impact: Successful exploitation will allow the attacker to execute arbitrary code in the context of an application. Impact Level: Application Affected Software/OS: PHP Server Monitor version 2.0.1 and prior Fix: No solution or patch is available as of 22nd November, 2012. Information regarding this issue will be updated once the solution details are available. For updates refer to http://sourceforge.net/projects/phpservermon/ References: http://www.exploit-db.com/exploits/22881/ http://packetstormsecurity.org/files/118254/PHP-Server-Monitor-Cross-Site-Scripting.html CVSS Score: 4.3 CVSS Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N |
Copyright | Copyright (C) 2012 Greenbone Networks GmbH |
Esta es sólo una de 58962 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |
|