CVE Vulnerabilities

CVE-2014-3877

Published: Jun 18, 2014 | Modified: Jun 18, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Incomplete blacklist vulnerability in Frams Fast File EXchange (F*EX, aka fex) before fex-20140530 allows remote attackers to conduct cross-site scripting (XSS) attacks via the addto parameter to fup.

Affected Software

Name Vendor Start Version End Version
Fex Ulli_horlacher * 20140313 (including)
Fex Ubuntu lucid *
Fex Ubuntu precise *
Fex Ubuntu saucy *
Fex Ubuntu trusty *
Fex Ubuntu upstream *

References