what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 1 of 1 RSS Feed

Files

ExpressionEngine-1.4.1.txt
Posted Jan 26, 2006
Authored by Aliaksandr Hartsuyeu | Site evuln.com

ExpressionEngine 1.4.1 does not sanatize the HTTP_REFERER variable. This can be used to post HTTP query with fake Referrer value which may contain arbitrary html or script code. This code will be executed when administrator(or any user) will open Referrer Statistics.

tags | exploit, web, arbitrary
SHA-256 | 269640d9a1082ed07f4dc3684cbd7cf0264bdf5992ad0cf57f58bf4c5ed91008
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
OpenAI's ChatGPT Targeted In Austrian Privacy Complaint
Posted Apr 29, 2024

tags | headline, government, privacy
Meta To Face EU Probe For Not Doing Enough To Stop Russian Disinformation
Posted Apr 29, 2024

tags | headline, government, russia, fraud, facebook, social
Powerful Brokewell Android Trojan Allows Device Takeover
Posted Apr 26, 2024

tags | headline, privacy, malware, phone, trojan, data loss, flaw, google, backdoor
Over 1,400 CrushFTP Instances Vulnerable To Exploited 0-Day
Posted Apr 26, 2024

tags | headline, hacker, data loss, flaw
Millions Of IPs Remain Infected By USB Worm Years After Its Creators Left It For Dead
Posted Apr 26, 2024

tags | headline, malware, backdoor
750 Million Vulnerable To Snooping From Chinese Keyboard Apps
Posted Apr 26, 2024

tags | headline, privacy, china, data loss, flaw
Nation-State Hackers Exploit Cisco Firewall Zero Days To Backdoor Government Networks
Posted Apr 25, 2024

tags | headline, hacker, government, cyberwar, cisco, backdoor
FTC Sending $5.6 Million To Ring Customers Over Security Failures
Posted Apr 25, 2024

tags | headline, government, privacy, usa, amazon, flaw
Palo Alto Networks Shares Remediation Advice
Posted Apr 25, 2024

tags | headline, flaw
Russia, Iran Pose Most Aggressive Threat To 2024 Election
Posted Apr 25, 2024

tags | headline, government, usa, russia, fraud, cyberwar, iran
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close