PT-2015-4202 · Efs · Easy File Sharing Web Server

Sick Psycko

·

Published

2015-01-02

·

Updated

2017-09-08

·

CVE-2014-9439

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Easy File Sharing Web Server version 6.8
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the username field during registration. This occurs because the input is not properly handled by the forum.ghp component.
Recommendations For Easy File Sharing Web Server version 6.8, consider restricting access to the registration feature until a proper fix is applied, and ensure that user input, especially in the username field, is properly sanitized to prevent XSS attacks.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-9439

Affected Products

Easy File Sharing Web Server