PT-2007-1301 · Fx-App · Fx-App
Luny
·
Published
2007-02-15
·
Updated
2018-10-16
·
CVE-2006-7022
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
fx-APP version 0.0.8.1
Description
The issue allows remote attackers to misrepresent the contents of a web page by providing an arbitrary URL in the
url parameter to a "showhtml" action for "index.php", causing the URL to be displayed within an iframe.Recommendations
For fx-APP version 0.0.8.1, consider restricting access to the "showhtml" action for "index.php" to minimize the risk of exploitation, and avoid using the
url parameter in the affected API endpoint until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fx-App