First published: Wed Dec 31 2003(Updated: )
Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple-file-manager | <=0.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1539 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2003-1539, upgrade to Simple File Manager version 0.21 or later which addresses this vulnerability.
CVE-2003-1539 can facilitate cross-site scripting attacks, allowing remote attackers to inject arbitrary web scripts or HTML.
CVE-2003-1539 affects Simple File Manager versions prior to 0.21.
Yes, CVE-2003-1539 can be exploited by manipulating file names and directory names to inject malicious scripts.