PT-2014-5569 · Frams · Frams' Fast File Exchange

Publicado

2014-06-18

·

Atualizado

2014-06-18

·

CVE-2014-3876

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Frams' Fast File EXchange (F*EX, aka fex) versions prior to fex-20140530
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the akey parameter to the "rup" endpoint, or through the disclaimer or gm parameters to the "fuc" endpoint.
Recommendations For versions prior to fex-20140530, consider disabling the rup and fuc endpoints until a patch is available. Restrict access to the akey, disclaimer, and gm parameters to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3876
DLA-68-1

Produtos afetados

Frams' Fast File Exchange