vendor:
Falcon Series One
by:
MhZ91
7.5
CVSS
HIGH
Multilple Remote File Inclusion, Permanent Xss
CWE
Product Name: Falcon Series One
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Falcon Series One – Multilple Remote File Inclusion + Permanent Xss
This exploit allows for remote file inclusion and permanent cross-site scripting. The vulnerability can be exploited through the sitemap.xml.php and errors.php pages. The permanent XSS can be executed through the input fields gb_mail, gb_name, and textarea gb_text on the index.php?guestbook=v page. Additionally, there is a CSRF exploit for changing passwords on the index.php?admin=changepass page.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the latest patch or update for Falcon Series One. Additionally, input validation and sanitization should be implemented to prevent remote file inclusion and cross-site scripting attacks.