The TRACKtheCLICK script is vulnerable to an injection attack due to the User-Agent and Referer variables not being filtered in click.cgi, allowing a malicious attacker to spoof incorrect information and when admin.cgi is opened, the injected code will be executed by the victim’s browser.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31811/trackclick.txt
Source: https://packetstormsecurity.com/files/31811/trackclick.txt.html

