|
Description
|
|
Two vulnerabilities have been identified in Nodez, which could be exploited by remote attackers to execute arbitrary commands and scripting code. These flaws are due to input validation errors in the "modules/system/load_node.inc" and "system/op_signin.inc" scripts that do not validate the "op" and "email" parameters, which could be exploited by malicious people to conduct cross site scripting attacks or inject malicious code into the "list.gtdat" file and then execute arbitrary commands via a local file inclusion.
|