PT-2002-1010 · Faq O Matic · Faq-O-Matic
Published
2002-05-03
·
Updated
2016-10-18
·
CVE-2002-0230
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Faq-O-Matic version 2.712
Description
The issue concerns a cross-site scripting vulnerability that allows remote attackers to execute arbitrary Javascript on other clients. This is achieved via the
cmd parameter in fom.cgi, which causes the script to be inserted into an error message. Additionally, there are multiple vulnerabilities in the faqomatic package that can lead to a breach of protected information integrity, and these can be exploited remotely.Recommendations
For Faq-O-Matic version 2.712, consider restricting access to the fom.cgi script until a patch is available, and avoid using the
cmd parameter in the affected API endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Faq-O-Matic