vendor:
NXFilter v3.0.3
by:
hyp3rlinx
7.5
CVSS
HIGH
Persistent & Reflected XSS
79
CWE
Product Name: NXFilter v3.0.3
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:nxfilter_project:nxfilter:3.0.3
Platforms Tested:
2015
NXFilter v3.0.3 – Persistent & Reflected XSS
Persistent & reflected XSS entry points exist allowing arbitrary client side browser code execution on victims who click our infected linx or visit persistently stored XSS payloads. XSS strings seem to get filtered, yet we can defeat that using JS String.fromCharCode() functions.