PT-2026-1678 · Unknown · Yahei-Php Proberv
Published
2026-01-07
·
Updated
2026-01-08
·
CVE-2019-25280
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Yahei-PHP Prober version 0.4.7
Description
The software contains a remote HTML injection issue that enables attackers to execute arbitrary HTML code. This is achieved by injecting malicious HTML code into the
speed GET parameter of the 'prober.php' file, which can lead to cross-site scripting within user browser sessions. The vulnerable parameter is speed. The API endpoint involved is 'prober.php'.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yahei-Php Proberv