Variable $_SERVER['HTTP_REFERER'] isn't properly sanitized. This can be
used to post HTTP query with fake Referer value which may contain arbitrary
html or script code. This code will be executed when administrator(or any
user) will open Referrers Statistics.
Administrator's session is threatened.
--------------Exploit----------------------
Available at: http://evuln.com/vulns/48/exploit.html
--------------Solution---------------------
No Patch available.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.