vendor:
Easypx41
by:
SecurityFocus
7.5
CVSS
HIGH
Variable Injection
94
CWE
Product Name: Easypx41
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
Easypx41 Multiple Variable Injection Vulnerabilities
An attacker can manipulate multiple script input variables and bypass access controls to retrieve sensitive and privileged information. Information obtained may aid in further attacks against the vulnerable application or the underlying system.
Mitigation:
Input validation should be used to ensure that user-supplied data is properly sanitized.