vendor:
XPhone UC Web
by:
Vulnerability Laboratory [Research Team] - Benjamin Kunz Mejri (bkm@vulnerability-lab.com)
3,5
CVSS
MEDIUM
Cross Site Scripting (XSS)
79
CWE
Product Name: XPhone UC Web
Affected Version From: 4.1.890SR1
Affected Version To: 4.1.890SR1
Patch Exists: YES
Related CWE: N/A
CPE: a:c4b:xphone_uc_web:4.1.890sr1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
C4B XPhone UC Web 4.1.890S R1 – Cross Site Vulnerability
The persistent Cross-Site Scripting vulnerability is located in the `name` value of the `contact` module. Remote attackers are able to inject own malicious script codes to the vulnerable application module. The execution of the malicious script code occurs in the `search` module of the `contact` module. The request method to inject is POST and the attack vector is located on the application-side of the service.
Mitigation:
Update to the latest version of the C4B XPhone UC Web v4.1.890SR1