source: https://www.securityfocus.com/bid/56626/info Feng Office is prone to a security-bypass vulnerability and an HTML-injection vulnerability. An attacker may leverage the HTML-injection issue to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. The attacker may leverage the security-bypass issue to bypass certain security restrictions and perform unauthorized actions in the affected application. Feng Office 2.2.1 and 2.0 Beta 3 are vulnerable; other versions may also be affected. # Expl0it/P0c/Xss ################### # Expl0it/P0c/Privilege Escalation ###################