Ulli Horlacher's vulnerability profile centers on FEX, a file-exchange utility designed for secure data transfer, with a durable signal around web-layer and authentication weaknesses including cross-site scripting and improper authentication mechanisms. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the authentication-critical nature of file-exchange applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ulli Horlacher over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0869MEDIUM Cross-site scripting (XSS) vulnerability in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20120215 allows remote attackers to inject arbitrary web script or HTML via the | Sep 25, 2012 | 4.3 | 25 | NO | YES |
CVE-2011-1409MEDIUM Frams's Fast File EXchange (F*EX, aka fex) 20100208, and possibly other versions before 20110610, allows remote attackers to bypass authentication and upload arbitrary files via a | Jun 24, 2011 | 5.0 | 19 | NO | NO |
CVE-2014-3875MEDIUM The addto parameter to fup in Frams' Fast File EXchange (F*EX, aka fex) before fex-2014053 allows remote attackers to conduct cross-site scripting (XSS) attacks | Nov 27, 2019 | 6.1 | 17 | NO | NO |
CVE-2012-1293MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in fup in Frams' Fast File EXchange (F*EX, aka fex) before 20111129-2 allow remote attackers to inject arbitrary web script or H | Sep 25, 2012 | 4.3 | 17 | NO | NO |
CVE-2014-3877MEDIUM Incomplete blacklist vulnerability in Frams' Fast File EXchange (F*EX, aka fex) before fex-20140530 allows remote attackers to conduct cross-site scripting (XSS) attacks via the ad | Jun 18, 2014 | 4.3 | 14 | NO | NO |
CVE-2014-3876MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Frams' Fast File EXchange (F*EX, aka fex) before fex-20140530 allow remote attackers to inject arbitrary web script or HTML v | Jun 18, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ulli Horlacher.
Media articles that mention a CVE ID that affects a product developed by Ulli Horlacher — matched by CVE ID, not by vendor name.