HIGH
common/safety.php in Aztek Forum 4.00 allows remote attackers to enter certain data containing %22 sequences (URL encoded double quotes) and other potentially dangerous manipulations by sending a cookie, which bypasses the blacklist matching against the GET and PUT superglobal arrays
Published Jan 30, 2007
7.5
HIGHCVSS 2.0
EPSS 1.58%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.