vendor:
Key Focus Web Server
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: Key Focus Web Server
Affected Version From: 3.1.2000
Affected Version To: 3.1.2000
Patch Exists: NO
Related CWE: CVE-2007-6053
CPE: a:keyfocus:key_focus_web_server:3.1.0
Platforms Tested:
2007
Cross-Site Scripting Vulnerability in Key Focus Web Server
The Key Focus Web Server application fails to properly sanitize user-supplied input, allowing an attacker to execute arbitrary script code in the browser of an unsuspecting user. This can lead to the theft of authentication credentials and other attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input and implement proper input validation and output encoding.