4.3

CVE-2012-1293

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20111129-2 allow remote attackers to inject arbitrary web script or HTML via the (1) to or (2) from parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ulli HorlacherFex Version <= 20111129
Ulli HorlacherFex Version20110609
Ulli HorlacherFex Version20110610
Ulli HorlacherFex Version20110614
Ulli HorlacherFex Version20110615
Ulli HorlacherFex Version20110616
Ulli HorlacherFex Version20110621
Ulli HorlacherFex Version20110622
Ulli HorlacherFex Version20110627
Ulli HorlacherFex Version20110630
Ulli HorlacherFex Version20110701
Ulli HorlacherFex Version20110714
Ulli HorlacherFex Version20110716
Ulli HorlacherFex Version20110722
Ulli HorlacherFex Version20110726
Ulli HorlacherFex Version20110727
Ulli HorlacherFex Version20110730
Ulli HorlacherFex Version20110731
Ulli HorlacherFex Version20110803
Ulli HorlacherFex Version20110807
Ulli HorlacherFex Version20110808
Ulli HorlacherFex Version20110809
Ulli HorlacherFex Version20110810
Ulli HorlacherFex Version20110811
Ulli HorlacherFex Version20110813
Ulli HorlacherFex Version20110826
Ulli HorlacherFex Version20110829
Ulli HorlacherFex Version20110830
Ulli HorlacherFex Version20110901
Ulli HorlacherFex Version20110905
Ulli HorlacherFex Version20110906
Ulli HorlacherFex Version20110907
Ulli HorlacherFex Version20110919
Ulli HorlacherFex Version20110920
Ulli HorlacherFex Version20110921
Ulli HorlacherFex Version20110930
Ulli HorlacherFex Version20111003
Ulli HorlacherFex Version20111005
Ulli HorlacherFex Version20111013
Ulli HorlacherFex Version20111028
Ulli HorlacherFex Version20111102
Ulli HorlacherFex Version20111108
Ulli HorlacherFex Version20111115
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.645
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.