vendor:
Yahei-PHP Proberv
by:
ManhNho
6.1
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Yahei-PHP Proberv
Affected Version From: 0.4.7
Affected Version To: 0.4.7
Patch Exists: YES
Related CWE: CVE-2018-9238
CPE: a:yahei:yahei-php_proberv:0.4.7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 / Kali Linux
2018
Yahei-PHP Proberv0.4.7 – Cross-Site Scripting
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.