vendor:
net2ftp
by:
cicatriz
N/A
CVSS
N/A
Cross-Site Scripting/Request Forgery
79,352
CWE
Product Name: net2ftp
Affected Version From: 0.97
Affected Version To: 0.98 beta
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
net2ftp <= 0.97 Cross-Site Scripting/Request Forgery
Multiple vulnerabilities were found on the package net2ftp [1], version 0.98 and below. Two types of vulnerabilities were found: Cross-Site Scripting and Cross-Site Request Forgery. Cross-Site Scripting (XSS) allows an attacker to inject malicious code on the vulnerable application. This code will be executed on the browser of the user who visits the vulnerable page. Cross-Site Request Forgery (CSRF) allows an attacker to perform actions on behalf of the user without his knowledge.
Mitigation:
The vendor didn't released any fix/update.