|
|
| |
| Fastream NETFile Server "(formerly the server part of FTP++ P2P) is supreme FTP and Web server combined together in one application". A vulnerability in the product allows remote attackers to cause the server to return arbitrary HTML and/or JavaScript. |
| |
Credit:
The information has been provided by Oliver Karow.
|
| |
Vulnerable systems:
* Fastream NetFile FTP/WebServer version 6.0 (6.0.3.588)
Requesting a non-existing URL will give a "404 Not Found" answer, containing the requested URL. It is not checked if the URL contains script code.
Example:
http://webserver/< script>alert("bang")</script>
|
|
|
|
|