PT-2015-4202 · Efs · Easy File Sharing Web Server

Sick Psycko

·

Publicado

2015-01-02

·

Atualizado

2017-09-08

·

CVE-2014-9439

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Easy File Sharing Web Server version 6.8
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the username field during registration. This occurs because the input is not properly handled by the forum.ghp component.
Recommendations For Easy File Sharing Web Server version 6.8, consider restricting access to the registration feature until a proper fix is applied, and ensure that user input, especially in the username field, is properly sanitized to prevent XSS attacks.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-9439

Produtos afetados

Easy File Sharing Web Server