vendor:
IMG2ASCII
by:
indoushka
7.5
CVSS
HIGH
Cross Site Scripting
79
CWE
Product Name: IMG2ASCII
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows SP2 Fran�ais V.(Pnx2 2.0) + Lunix Fran�ais v.(9.4 Ubuntu)
2009
IMG2ASCII Cross Site Scripting Vulnerability
A Cross Site Scripting vulnerability exists in IMG2ASCII � Ueli Weiss, which allows remote attackers to inject arbitrary web script or HTML via the dbhost, dbbase, dbuser, and dbpass parameters in install.php, and the ascii.php parameter.
Mitigation:
Input validation should be used to prevent Cross Site Scripting attacks.