Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

CMS Faethon Cross Site Scripting Vulnerability and Remote File Include Vulnerability

CMS Faethon is prone to a cross-site scripting vulnerability and a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

Attackers can exploit these issues to execute arbitrary code within the context of the webserver process, execute script code in a user's browser, steal cookie-based authentication credentials, and launch other attacks.

CMS Faethon 2.2 is vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2007, SecurityFocus