ISS Proventia GX Series Cross Site Scripting and File Inclusion Vulnerabilities
Description
Multiple vulnerabilities have been identified in Proventia GX5108 and GX5008, which could be exploited by attackers to execute arbitrary scripting code or by malicious users to disclose sensitive information.
The first issue is caused by an input validation error in the "alert.php" script that does not validate the "reminder" parameter, which could be exploited by attackers to cause malicious scripting code to be executed by the user's browser.
The second vulnerability is caused by an input validation error in the "main.php" script when processing the "page" parameter, which could be exploited by malicious administrators to include remote or local files with the privileges of the application.
Vulnerable Products
Vulnerable Software: ISS Proventia GX5108ISS Proventia GX5008