FileRun application has many vulnerabilities such as cross-site scripting, open redirection, directory listing..
FileRun Vulnerabilities and Exploits
FileRun application has many vulnerabilities
CVE-2019-12457 - CVE-2019-12458 - CVE-2019-12459 - CVE-2019-12905
PoC - XSS
cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2019-12905
To exploit vulnerability, someone could upload an allowed file named “><img src=x onerror=prompt(documentdomain)> to impact users w