vendor:
Dome Firewall
by:
Ozer Goker
5.5
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Dome Firewall
Affected Version From: 2.7.2000
Affected Version To: 2.7.2000
Patch Exists: NO
Related CWE:
CPE: comodo:dome_firewall:2.7.0
Platforms Tested:
2019
Comodo Dome Firewall 2.7.0 | Cross-Site Scripting
This exploit allows an attacker to inject malicious scripts into the Comodo Dome Firewall software, specifically in the 'username', 'comment', and 'admin_name' parameters. The payload used in the exploit triggers an alert pop-up with the specified message.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input and implement proper output encoding. Additionally, regular security updates and patches should be applied to the Comodo Dome Firewall software.