Recent Posts
- SnortReport nmap.php target Parameter Arbitrary Command Execution
- Privacy in iTunes Ping
- Mandriva: 2010:170: wget
- New Bento 3 Project Manager
- Gentoo: 201009-01: wxGTK: User-assisted execution of arbitrary code
Categories
- Apple Security Updates
- CVE Vulnerabilities
- Debian Advisories
- Fedora Advisories
- Foresight Advisories
- FreeBSD Advisories
- Gentoo Advisories
- Linux Vulnerabilities
- Mandriva Advisories
- Microsoft Security Response Center
- Microsoft Vulnerabilities
- Nessus Plugin Updates
- Product Updates
- Red Hat Advisories
- Slackware Advisories
- Suse Advisories
- Ubuntu Advisories
ClarkConnect proxy.php url Parameter XSS
Synopsis : The remote web server hosts a PHP script that is prone to a cross- site scripting attack. Description : The remote web server is used by ClarkConnect, an Internet server and gateway product, to process PHP scripts used for configuration. The installed version includes a script, ‘/public/proxy.php’, that fails to sanitize user- supplied input to the ‘url’ parameter before using it to generate dynamic HTML output
Read the original:
ClarkConnect proxy.php url Parameter XSS

Leave a Comment