Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a 403 Forbidden error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Delegate | Delegate | 7.7.0 (including) | 7.7.0 (including) |
Delegate | Delegate | 7.7.1 (including) | 7.7.1 (including) |
Delegate | Delegate | 7.8.0 (including) | 7.8.0 (including) |
Delegate | Delegate | 7.8.1 (including) | 7.8.1 (including) |