OpenWGA Content Manager 7.1.9 User-Agent HTTP Header XSS

Discussion in 'News Aggregator' started by Packet Storm, 14 Apr 2016.

  1. Packet Storm

    Packet Storm Guest

    OpenWGA suffers from a cross-site scripting vulnerability when input passed via the User-Agent HTTP header is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

    Continue reading...
     

Share This Page

Loading...