[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cerberus FTP Server via a crafted log entry

ID: oval:org.secpod.oval:def:8257Date: (C)2013-01-07   (M)2022-10-10
Class: VULNERABILITYFamily: windows




The host is installed with Cerberus FTP Server before 5.0.6.0 and is prone to multiple cross site scripting vulnerabilities. The flaws are present in the application, which fails to handle a crafted log file. Successful exploitation could allow attackers to inject arbitrary web script.

Platform:
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows 7
Product:
Cerberus FTP Server
Reference:
CVE-2012-6339
CVE    1
CVE-2012-6339
CPE    133
cpe:/a:cerberusftp:ftp_server:1.2
cpe:/a:cerberusftp:ftp_server:4.0.0.11
cpe:/a:cerberusftp:ftp_server:1.1
cpe:/a:cerberusftp:ftp_server:1.7
...

© SecPod Technologies