Yahei-PHP Prober 0.4.7 contains a remote HTML injection vulnerability that allows attackers to execute arbitrary HTML code through the 'speed' GET parameter. Attackers can inject malicious HTML code in the 'speed' parameter of prober.php to trigger cross-site scripting in user browser sessions.
Metrics
Affected Vendors & Products
References
History
Thu, 08 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Jan 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yahei
Yahei yahei Php Prober |
|
| Vendors & Products |
Yahei
Yahei yahei Php Prober |
Wed, 07 Jan 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Yahei-PHP Prober 0.4.7 contains a remote HTML injection vulnerability that allows attackers to execute arbitrary HTML code through the 'speed' GET parameter. Attackers can inject malicious HTML code in the 'speed' parameter of prober.php to trigger cross-site scripting in user browser sessions. | |
| Title | Yahei-PHP Prober 0.4.7 Remote HTML Injection via Speed Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-07T23:11:07.955Z
Updated: 2026-01-08T18:16:43.143Z
Reserved: 2026-01-06T16:07:08.526Z
Link: CVE-2019-25280
Updated: 2026-01-08T15:06:52.287Z
Status : Awaiting Analysis
Published: 2026-01-08T00:15:58.280
Modified: 2026-01-08T19:15:55.207
Link: CVE-2019-25280
No data.