header-logo
Suggest Exploit
vendor:
Fuzzylime
by:
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: Fuzzylime
Affected Version From: 1.01b
Affected Version To: 1.01b
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:

Cross-Site Scripting Vulnerability in Fuzzylime

Fuzzylime is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. Exploiting this vulnerability may allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected website. As a result, the attacker may be able to steal cookie-based authentication credentials and to launch other attacks.

Mitigation:

To mitigate this vulnerability, it is recommended to properly sanitize and validate user-supplied input before using it in web applications.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/24522/info

Fuzzylime is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

Exploiting this vulnerability may allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected website. As a result, the attacker may be able to steal cookie-based authentication credentials and to launch other attacks.

Fuzzylime 1.01b and prior versions are vulnerable to this issue. 

http://www.example.com/path/low.php?action=log&fromforum=111-222-1933email@address.com&fromtopic=111-222-1933email@address.com&fromaction=>"><ScRiPt%20%0a%0d>alert(21 407654)%3B</ScRiPt>