shadoweb wdja v1.5.1 is susceptible to cross-site scripting because it allows attackers to execute arbitrary code and gain escalated privileges via the backurl parameter to /php/passport/index.php.Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view