Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Nicola Fioravanti

Pesquisador demuuratsalo experimental hack lab
#30405de 53,639
8.6CVSS total
Vulnerabilidades · 2
Média
2
PT-2012-2922
4.3
2012-09-25
Frams · Frams' Fast File Exchange · CVE-2012-0869
**Name of the Vulnerable Software and Affected Versions** Frams' Fast File EXchange (F*EX, aka fex) versions prior to 20120215 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the `id` parameter. This can lead to the execution of malicious scripts on the client-side. **Recommendations** For versions prior to 20120215, update to version 20120215 or later to resolve the issue. As a temporary workaround, consider restricting access to the `id` parameter in the affected API endpoint until the issue is resolved.
PT-2012-3181
4.3
2012-09-25
Fex · F*Ex · CVE-2012-1293
**Name of the Vulnerable Software and Affected Versions** F*EX (aka fex) versions prior to 20111129-2 **Description** The issue allows remote attackers to inject arbitrary web script or HTML via the `to` or `from` parameters, potentially leading to cross-site scripting (XSS) attacks. **Recommendations** For versions prior to 20111129-2, update to version 20111129-2 or later to resolve the issue.