vendor:
EZGenerator
by:
SecurityFocus
7,5
CVSS
HIGH
Local File Disclosure and CSRF
20, 352
CWE
Product Name: EZGenerator
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
EZGenerator Local File Disclosure and CSRF Vulnerabilities
EZGenerator is prone to a local file-disclosure vulnerability and a cross-site request-forgery vulnerability. An attacker may leverage these issues to perform unauthorized actions in the context of a logged-in user, or obtain sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
Mitigation:
Ensure that all user input is validated and filtered before being used in the application. Ensure that the application is not vulnerable to cross-site request forgery attacks. Ensure that the application is not vulnerable to local file disclosure attacks.