vendor:
PsychoStats
by:
Jason Morriss
7,5
CVSS
HIGH
Cross Site Scripting
79
CWE
Product Name: PsychoStats
Affected Version From: <= 2.2.4 Beta
Affected Version To: <= 2.2.4 Beta
Patch Exists: YES
Related CWE: CVE-2004-1417
CPE: 2.2.4 Beta
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2004
PsychoStats Cross Site Scripting
Cross site scripting exists in Jason Morriss PsychoStats. This vulnerability exists due to user supplied input not being checked properly. Below is an example. http://www.example.com/stats/login.php?login=%22%3E%3Ciframe%3E This vulnerability could be used to steal cookie based authentication credentials within the scope of the current domain, or render hostile code in a victim's browser.
Mitigation:
The vendor was contacted, responded very prompt and released a patch.