4.3
CVSSv2

CVE-2011-4572

Published: 29/11/2011 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions prior to 1.4.2 allows remote malicious users to inject arbitrary web script or HTML via the q parameter. NOTE: this was originally reported as a file disclosure vulnerability, but this is likely inaccurate.

Vulnerable Product Search on Vulmon Subscribe to Product

codefuture cf image hosting script 1.4.1

codefuture cf image hosting script 1.3.82

Exploits

#!/usr/bin/perl #CF Image Hosting Script 1382 File Disclosure Exploit #Bugfounder and Exploitcoder: bd0rk #Contact: wwwsohcrewschool-of-hacknet #eMail: bd0rk[at]hackermailcom #Affected-Software: CF Image Hosting Script 1382 #Vendor: wwwphpkodecom #Download: phpkodecom/download/p/CF_Image_Hosting_v13zip #Vulnerable Code ...