| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.803109 |
| Category: | Web application abuses |
| Title: | PHP Server Monitor Multiple Stored Cross-Site Scripting Vulnerabilities |
| Summary: | Check if PHP Server Monitor is vulnerable to Cross-Site Scripting |
| Description: | Overview: This host is installed with PHP Server Monitor and is prone to multiple stored cross-site scripting vulnerabilities. Vulnerability Insight: The flaws are due improper validation of user-supplied input passed via the 'label' and 'name' parameter to 'index.php', that allows attackers to execute arbitrary HTML and script code on the web server. Impact: Successful exploitation will allow the attacker to execute arbitrary code in the context of an application. Impact Level: Application Affected Software/OS: PHP Server Monitor version 2.0.1 and prior Fix: No solution or patch is available as of 22nd November, 2012. Information regarding this issue will be updated once the solution details are available. For updates refer to http://sourceforge.net/projects/phpservermon/ References: http://www.exploit-db.com/exploits/22881/ http://packetstormsecurity.org/files/118254/PHP-Server-Monitor-Cross-Site-Scripting.html |
| Copyright | Copyright (C) 2012 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|