MemHT Portal "User-Agent" HTTP Header HTML Injection

  Bookmark
 and Share

MemHT Portal is a content manager. The application is exposed to an HTML injection issue because it fails to properly sanitize user-supplied input to the "User-Agent" HTTP Header in the "inc/inc_getinfo.php" script. MemHT Portal version 4.0.1 is affected.

Ref: http://www.memht.com/news_149_MemHT-Portal-4-0-2.html

10.49.37 - CVE: Not Available
Platform: Web Application