Cross Site Scripting vulnerability in ACG-faka v1.1.7 allows a remote attacker to execute arbitrary code via the encode parameter in Index.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/lizhipay/acg-faka/issues/72 | third party advisory issue tracking exploit |
https://gist.github.com/N0boy-0/7251856fed517eb6358d8cae03099b7b | third party advisory |