vendor:
GaliX
by:
John Martinelli
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: GaliX
Affected Version From: 2
Affected Version To: 2
Patch Exists: NO
Related CWE:
CPE: a:galix:galix:2.0
Platforms Tested:
2007
GaliX Cross-Site Scripting Vulnerability
GaliX is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials and to launch other attacks.
Mitigation:
To mitigate this vulnerability, ensure that all user-supplied data is properly sanitized and validated before being used in web applications.