vendor:
Flatnux
by:
gmda
7.5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: Flatnux
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Flatnux Grabber Cookies Visitor
Flatnux is vulnerable to Cross-Site Scripting (XSS) attacks. An attacker can inject malicious code into the application by registering and logging in, and using the HTML code provided in the exploit. This code will execute a JavaScript that will grab the cookies of the visitor and send them to the attacker's website.
Mitigation:
Input validation should be used to prevent malicious code from being injected into the application.