vendor:
osCSS
by:
Unknown
5.5
CVSS
MEDIUM
Cross-Site Scripting and Local File Include
79
CWE
Product Name: osCSS
Affected Version From: 2.1.0 RC12
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested:
Unknown
osCSS Cross-Site Scripting and Local File Include Vulnerabilities
osCSS is prone to a cross-site scripting vulnerability and multiple local file-include vulnerabilities because the application fails to sufficiently sanitize user-supplied data. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and open or run arbitrary files in the context of the webserver process.
Mitigation:
Unknown