vendor:
Xedus
by:
5.5
CVSS
MEDIUM
Denial of Service, Cross-Site Scripting, Directory Traversal
285, 79, 22
CWE
Product Name: Xedus
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Xedus Multiple Vulnerabilities
Xedus is susceptible to multiple vulnerabilities. The first vulnerability is a denial of service vulnerability that prevents legitimate users from accessing the hosted site. The second vulnerability is a cross-site scripting vulnerability in included sample scripts, allowing an attacker to inject malicious code. The third vulnerability is a directory traversal vulnerability, which allows an attacker to read arbitrary files outside of the configured web root.
Mitigation:
To mitigate these vulnerabilities, it is recommended to upgrade to a patched version of Xedus or apply the necessary security patches. Additionally, input validation and sanitization should be implemented to prevent cross-site scripting and directory traversal attacks.