vendor:
F@cile Interactive Web
by:
nukedx.com, milw0rm.com
7.5
CVSS
HIGH
File Inclusion Vulnerabilities, Cross Site Scripting, Information disclosure
94, 79, 200
CWE
Product Name: F@cile Interactive Web
Affected Version From: 0.8x
Affected Version To: 0.8x
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
F@cile Interactive Web <= 0.8x Multiple Remote Vulnerabilities
This exploits works on F@cile Interactive Web <= 0.8x. It includes File Inclusion Vulnerabilities, Cross Site Scripting, and Information disclosure. The File Inclusion Vulnerabilities can be exploited by sending a malicious URL to the victim. The Cross Site Scripting can be exploited by sending a malicious URL with XSS payloads. The Information disclosure can be exploited by sending a malicious URL with an etc/passwd payload.
Mitigation:
The user should update to the latest version of F@cile Interactive Web and apply the necessary patches.