Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-1609. PoCs published by SEC Consult.
AI-analyzed exploit summary This is a detailed security advisory from SEC Consult describing multiple vulnerabilities in Micro Focus Filr, including CSRF, OS command injection, XSS, and authentication bypass. It includes proof-of-concept code for exploiting these vulnerabilities.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input, as demonstrated by a crafted attribute of an IMG element in the phone field of a user profile.
Exploits (1)
This is a detailed security advisory from SEC Consult describing multiple vulnerabilities in Micro Focus Filr, including CSRF, OS command injection, XSS, and authentication bypass. It includes proof-of-concept code for exploiting these vulnerabilities.
References (6)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N