This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Faq-O-Matic First view 2002-05-16
Product Faq-O-Matic Last view 2002-05-16
Version Type
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:faq-o-matic:faq-o-matic:2.712:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
5 2002-05-16 CVE-2002-0230

Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message.

Open Source Vulnerability Database (OSVDB)

id Description
8661 Faq-O-Matic fom.cgi cmd Parameter Error Message XSS

OpenVAS Exploits

id Description
2008-01-17 Name : Debian Security Advisory DSA 109-1 (faqomatic)
File : nvt/deb_109_1.nasl
2005-11-03 Name : Various dangerous cgi scripts
File : nvt/dangerous_cgis.nasl
2005-11-03 Name : Faq-O-Matic fom.cgi XSS
File : nvt/faq_o_matic_xss.nasl

Snort® IPS/IDS

Date Description
2014-01-10 Faq-O-Matic fom.cgi access
RuleID : 2208-community - Type : SERVER-WEBAPP - Revision : 17
2014-01-10 Faq-O-Matic fom.cgi access
RuleID : 2208 - Type : SERVER-WEBAPP - Revision : 17

Nessus® Vulnerability Scanner

id Description
2004-10-21 Name: A web CGI is vulnerable to cross-site scripting attacks.
File: faq_o_matic_xss.nasl - Type: ACT_GATHER_INFO
2004-09-29 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-109.nasl - Type: ACT_GATHER_INFO
2003-06-17 Name: The remote web server may contain some dangerous CGI scripts.
File: dangerous_cgis.nasl - Type: ACT_ATTACK