Vulnerability Description
The addto parameter to fup in Frams' Fast File EXchange (F*EX, aka fex) before fex-2014053 allows remote attackers to conduct cross-site scripting (XSS) attacks
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ulli Horlacher | Fex | < 2014053 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/126906/F-EX-20140313-1-HTTP-Response-SplittExploitPatchThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Jun/1ExploitMailing ListPatch
- http://www.openwall.com/lists/oss-security/2014/06/03/6ExploitMailing ListPatch
- http://www.securityfocus.com/bid/67783Third Party AdvisoryVDB Entry
- https://security-tracker.debian.org/tracker/CVE-2014-3875Third Party Advisory
- http://packetstormsecurity.com/files/126906/F-EX-20140313-1-HTTP-Response-SplittExploitPatchThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Jun/1ExploitMailing ListPatch
- http://www.openwall.com/lists/oss-security/2014/06/03/6ExploitMailing ListPatch
- http://www.securityfocus.com/bid/67783Third Party AdvisoryVDB Entry
- https://security-tracker.debian.org/tracker/CVE-2014-3875Third Party Advisory
FAQ
What is CVE-2014-3875?
CVE-2014-3875 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The addto parameter to fup in Frams' Fast File EXchange (F*EX, aka fex) before fex-2014053 allows remote attackers to conduct cross-site scripting (XSS) attacks
How severe is CVE-2014-3875?
CVE-2014-3875 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3875?
Check the references section above for vendor advisories and patch information. Affected products include: Ulli Horlacher Fex.