vendor:
Istgah
by:
indoushka
7,5
CVSS
HIGH
XSS, Bypass, Backup
79, 287, 522
CWE
Product Name: Istgah
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2009
Istgah for Centerhost Mullti Vulnerability
The vulnerability allows an attacker to inject malicious JavaScript code into the application via the 'id' parameter in the 'view_ad.php' script. An attacker can also bypass authentication by accessing the 'cpindex.html' page. Additionally, an attacker can access the 'backup' directory without authentication.
Mitigation:
Input validation should be used to prevent the injection of malicious code. Authentication should be enforced for all sensitive pages.