Cross-site scripting (XSS) vulnerability in auth.w in djeyl.net WebMod 0.48 Half-Life Dedicated Server plugin allows remote attackers to inject arbitrary web script or HTML via the redir parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://osvdb.org/37833 | vdb entry |
http://sla.ckers.org/forum/read.php?3%2C44%2C11482#msg-11482 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/37220 | vdb entry |
http://secunia.com/advisories/27245 | third party advisory vendor advisory |
http://www.attrition.org/pipermail/vim/2007-October/001833.html | mailing list |
http://www.securityfocus.com/bid/26087 | vdb entry |