vendor:
My Little Forum
by:
7.5
CVSS
HIGH
Cross-Site Request Forgery, Stored Cross-Site Scripting, CSRF Allow To Backup Disclosure
CWE
Product Name: My Little Forum
Affected Version From: 2.3.2007
Affected Version To: 2.3.2007
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
My Little Forum 2.3.7 – Multiple Vulnerability
This WebApplication is vulnerable and suffer from some vulnerability. The first exploit is a CSRF (Cross-Site Request Forgery) where an attacker can add a page to the web app. The second exploit is a Stored XSS (Cross-Site Scripting) where an attacker can inject malicious scripts into the page. The third exploit is a Backup Disclosure vulnerability where an attacker can delete the htaccess file in the backup folder.