F*EX 20100208/20111129-2 - Multiple Cross-Site Scripting Vulnerabilities
Author: muuratsalo type: webapps platform: php port: date_added: 2012-02-20 date_updated: 2015-04-29 verified: 1 codes: CVE-2012-0869;OSVDB-79420 tags: aliases: screenshot_url: application_url: raw file: 36851.txt
source: https://www.securityfocus.com/bid/52085/info F*EX is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data. Exploiting these issues could allow an attacker to execute arbitrary script on the affected server and steal cookie-based authentication credentials. Other attacks are also possible. http://www.example.com/fup [id parameter] http://www.example.com/fup [to parameter] http://www.example.com/fup [from parameter]