vendor:
Icy Phoenix
by:
Saif El-Sherei
7.5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Icy Phoenix
Affected Version From: Icy Phoenix 1.3.0.53a
Affected Version To: Icy Phoenix 1.3.0.53a
Patch Exists: YES
Related CWE: N/A
CPE: a:icy_phoenix:icy_phoenix:1.3.0.53a
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FF 3.0.15, IE 8
2011
Icy Phoenix 1.3.0.53a http referer stored XSS
There is a stored XSS vulnerability using http referer HTTP header due to failure in 'index.php' in the acp to sanitize the http referer header. Any visitor to the site can compromise the admin account or any user with privileges to see the 'http referrers' section under the 'Info' section. An attacker has to use an intercepting proxy or manual server requests to add the 'HTTP referer header' containing the POC to the server request.
Mitigation:
Sanitize the http referer header in 'index.php' in the acp.