vendor:
glFusion
by:
High-Tech Bridge Security Research Lab
4,3
CVSS
MEDIUM
Cross-Site Scripting [CWE-79]
79
CWE
Product Name: glFusion
Affected Version From: 1.2.2
Affected Version To: 1.2.2
Patch Exists: YES
Related CWE: CVE-2013-1466
CPE: a:glfusion:glfusion:1.2.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mozilla Firefox (18.0.1)
2013
Multiple Cross-Site Scripting (XSS) in glFusion
High-Tech Bridge Security Research Lab discovered multiple XSS vulnerabilities in glFusion, which can be exploited to perform Cross-Site Scripting attacks. glFusion has a 'bad_behaviour' plugin (installed by default) that verifies HTTP Referer, aimed to protect against spambots. The plugin also makes reflected XSS attacks against the application a little bit more complex. To bypass the security restriction PoC (Proof-of-Concept) codes for vulnerabilities 1.1 – 1.3 modify the HTTP Referer header. These PoCs were successfully tested in the latest available version of Mozilla Firefox (18.0.1).
Mitigation:
Fixed by Vendor