acFreeProxy Cross Site Scripting Vulnerability
BID:6236
Info
acFreeProxy Cross Site Scripting Vulnerability
| Bugtraq ID: | 6236 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2002 12:00AM |
| Updated: | Nov 25 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Matthew Murphy" <[email protected]>. |
| Vulnerable: |
acFreeProxy acFreeProxy 1.33 -beta7 |
| Not Vulnerable: | |
Discussion
acFreeProxy Cross Site Scripting Vulnerability
It has been reported that acFreeProxy is prone to cross site scripting attacks.
As this vulnerability exists in acFreeProxy, it is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user, in the context of any domain.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the vulnerable software.
It has been reported that acFreeProxy is prone to cross site scripting attacks.
As this vulnerability exists in acFreeProxy, it is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user, in the context of any domain.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the vulnerable software.
Exploit / POC
acFreeProxy Cross Site Scripting Vulnerability
There is no exploit code required.
There is no exploit code required.