An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the info.php page.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/jianyan74/rageframe2 | product third party advisory |
http://rageframe2.com | broken link url repurposed |
https://github.com/jianyan74/rageframe2/issues/106 | third party advisory exploit |
https://github.com/jianyan74/rageframe2/issues/106?by=xboy%28Topsec%29 |