在 Paessler PRTG Network Monitor 版本低于 26.2.120.1449 的版本中,存在一个反射型跨站脚本(XSS)漏洞。当向一个以“.htm”结尾但不存在的资源发送请求时,Web 界面会返回一个 HTTP 403 “Forbidden Path”错误页面,该页面会将请求的 URL 路径直接回显到 HTML 响应体中,且未进行适当的输出编码或清理。 未认证的远程攻击者可以构造一个在路径中包含 HTML/JavaScript 恶意载荷的 URL(例如 https:////welcome.h
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Paessler GmbH | PRTG Network Monitor | 0 ~ 26.2.120.1449 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet