Affected configuration(s):
cpe:/a:ulli_horlacher:fex:20140313
Date published: 2014-06-18T10:55:12.960-04:00
Date last modified: 2014-06-18T14:27:01.340-04:00
CVSS Score: 4.3
Principal attack vector: NETWORK
Complexity: MEDIUM
Reference URL: http://fex.rus.uni-stuttgart.de/fex.html
Summary: Incomplete blacklist vulnerability in Frams’ Fast File EXchange (F*EX, aka fex) before fex-20140530 allows remote attackers to conduct cross-site scripting (XSS) attacks via the addto parameter to fup.