Description
|
|
Multiple vulnerabilities have been identified in Connect Daily, which may be exploited by attackers to execute arbitrary scripting code. These flaws are due to input validation errors in the "dedicated_order.php", "shared_order.php", "customers/server_management.php" and "customers/forgotpass.php" scripts that do not validate the "dedicatedPlanID", "sharedPlanID", "plan_id" and "customerEmailAddress" parameters, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
|