Description
|
|
Multiple vulnerabilities have been identified in iFlance, which may be exploited by attackers to execute arbitrary scripting code. These flaws are due to input validation errors in the "acc_verify.php", "admincp/login.php", "account/login.php", and "action/create.php" scripts that do not validate the "vk", "adminU", "user", "pass", and "project_name" parameters, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
|