PT-2014-5569 · Frams · Frams' Fast File Exchange

Published

2014-06-18

·

Updated

2014-06-18

·

CVE-2014-3876

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Frams' Fast File EXchange (F*EX, aka fex) versions prior to fex-20140530
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the akey parameter to the "rup" endpoint, or through the disclaimer or gm parameters to the "fuc" endpoint.
Recommendations For versions prior to fex-20140530, consider disabling the rup and fuc endpoints until a patch is available. Restrict access to the akey, disclaimer, and gm parameters to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3876
DLA-68-1

Affected Products

Frams' Fast File Exchange