diag_ping.php: Potential XSS via Hostname parameter
Plus Target Version:
On diag_ping.php, the hostname isn't fully validated and the output is not encoded, leading to a potential XSS.
Using an input such as the following example demonstrates the problem:
127.0.0.1 <img src='' onerror='alert()'>