Description
|
|
A vulnerability has been identified in E-Blah Platinum, which may be exploited by attackers to execute arbitrary scripting code. This flaw is due to input validation errors in the "cgi-bin/forum/Code/Routines.pl" script that does not validate the "HTTP_REFERER" header before being written to log files, which may be exploited by attackers to cause arbitrary scripting code to be executed by the administrator's browser when displaying logs.
|