vendor:
Endpoint Protector
by:
Juan Manuel Garcia
5.8
CVSS
MEDIUM
Permanent Cross-Site Scripting (XSS)
79
CWE
Product Name: Endpoint Protector
Affected Version From: Endpoint Protector v4.0.4.2
Affected Version To: Endpoint Protector v4.0.4.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Any running Endpoint Protector v4.0.4.2
2012
Multiple Persistent Cross-Site Scripting (XSS) in Endpoint Protector
Multiple Persistent Cross-Site vulnerabilities were found in Endpoint Protector v4.0.4.2, because the application fails to sanitize the response before it is returned to the user. This can be exploited to execute arbitrary script and HTML code in a user's browser session. This may allow the attacker to steal the user's cookie and to launch further attacks.
Mitigation:
The vendor has acknowledged the vulnerability but has not provided a patch.