Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Easy File Sharing Web Server Information Disclosure and Input Validation Vulnerabilities

Easy File Sharing Web Server is prone to information-disclosure and input-validation vulnerabilities. The application fails to properly sanitize user-supplied input before using it in dynamically generated content.

The issues include HTML-injection, cross-site scripting, and arbitrary information-disclosure vulnerabilities.

An attacker can exploit these issues to steal cookie-based authentication credentials, control how the site is rendered to the user, and gain access to otherwise confidential information. Successful exploits may facilitate a compromise of the underlying computer.

Version 4.0 of Easy File Sharing Web Server is vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus