Description
FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its search engine via the search parameter to the default URI. Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-17248 | FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its search engine via the search parameter to the default URI. Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed. |
References
| Link | Providers |
|---|---|
| https://www.exploit-db.com/exploits/43567/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T05:40:50.651Z
Reserved: 2018-01-12T00:00:00.000Z
Link: CVE-2018-5479
No data.
Status : Modified
Published: 2018-01-15T16:29:00.190
Modified: 2024-11-21T04:08:53.100
Link: CVE-2018-5479
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD