vendor:
Link Protect
by:
Shichemt Alen
7,5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: Link Protect
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: NO
Related CWE: None
CPE: None
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2 DE & Ubuntu 10.10
2010
Link Protect 1.2 XSS Vulnerabilities
Link Protect 1.2 is vulnerable to Cross-Site Scripting (XSS) attacks. An attacker can inject malicious JavaScript code into the 'description', 'name', 'email' or 'link' fields of the 'linkcheck.php', 'contact_us.php' and 'signup.php' pages. This malicious code will be executed in the browser of the victim when they visit the vulnerable page.
Mitigation:
Input validation should be used to prevent XSS attacks.