vendor:
Free Discussion Forum
by:
Abysssec Inc
8,8
CVSS
HIGH
Access to Admin's Section and Persistent XSS
79
CWE
Product Name: Free Discussion Forum
Affected Version From: Free Discussion Forum 1.0
Affected Version To: Free Discussion Forum 1.0
Patch Exists: YES
Related CWE: N/A
CPE: freediscussionforums.net
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014
FreeDiscussionForums Multiple Remote Vulnerabilities
This version of FreeDiscussionForums have Multiple Valnerabilities : Access to Admin's Section and Persistent XSS. With this path you can easily access to Admin's section: http://Example.com/ManageSubject.aspx. Valnerable Code : DLL : App_Web_wngcbiby.dll, Class : Class adminlogin. In this application also there is a Persistent XSS exist in title field. Valnerable Code : DLL : App_Web_wngcbiby.dll, Class : Class AddPost
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.