Vulnerability Description
Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this was originally reported as a file disclosure vulnerability, but this is likely inaccurate.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codefuture | Cf Image Hosting Script | 1.3.82 |
Related Weaknesses (CWE)
References
- http://osvdb.org/76059
- http://packetstormsecurity.org/files/view/105524/cfimagehosting1382-disclose.txtExploit
- http://secunia.com/advisories/46290Vendor Advisory
- http://www.exploit-db.com/exploits/17927Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70347
- http://osvdb.org/76059
- http://packetstormsecurity.org/files/view/105524/cfimagehosting1382-disclose.txtExploit
- http://secunia.com/advisories/46290Vendor Advisory
- http://www.exploit-db.com/exploits/17927Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70347
FAQ
What is CVE-2011-4572?
CVE-2011-4572 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to inject arbitrary web scri...
How severe is CVE-2011-4572?
CVE-2011-4572 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-4572?
Check the references section above for vendor advisories and patch information. Affected products include: Codefuture Cf Image Hosting Script.