/// File Name: |
ExpressionEngine-1.4.1.txt |
Description:
|
ExpressionEngine 1.4.1 does not sanatize the HTTP_REFERER variable. This can be used to post HTTP query with fake Referrer value which may contain arbitrary html or script code. This code will be executed when administrator(or any user) will open Referrer Statistics.
|
Author: | Aliaksandr Hartsuyeu |
Homepage: | http://evuln.com/vulns/48/summary.html |
File Size: | 1137 |
Last Modified: | Jan 26 11:16:04 2006 |
MD5 Checksum: | de8a40d525006723af46d5ab925d4feb |