Environment variable 'HTTP_REFERER' isn't properly sanitized. This can be
used to post HTTP query with fake Referer value which may contain arbitrary
html or script code. This code will be executed when administrator will
open "Click Log".
Administrator's login and password are threatened.
--------------Exploit----------------------
Available at: http://evuln.com/vulns/83/exploit.html
--------------Solution---------------------
Vendor-provided patch is available here:
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.