PT-2026-1678 · Unknown · Yahei-Php Proberv
CVE-2019-25280
·
Publicado
2026-01-07
·
Atualizado
2026-01-08
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Yahei-PHP Prober version 0.4.7
Description
The software contains a remote HTML injection issue that enables attackers to execute arbitrary HTML code. This is achieved by injecting malicious HTML code into the
speed GET parameter of the 'prober.php' file, which can lead to cross-site scripting within user browser sessions. The vulnerable parameter is speed. The API endpoint involved is 'prober.php'.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Yahei-Php Proberv