Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.803073
Kategorie:Web application abuses
Titel:Simple Invoices Multiple Cross Site Scripting Vulnerabilities
Zusammenfassung:This host is running Simple Invoices and is prone to multiple; cross site scripting vulnerabilities.
Beschreibung:Summary:
This host is running Simple Invoices and is prone to multiple
cross site scripting vulnerabilities.

Vulnerability Insight:
Input passed via the 'having' parameter to index.php
(when 'module' and 'view' are set to different actions) is not properly
sanitised before it is returned to the user.

Vulnerability Impact:
Successful exploitation will allow attacker to insert arbitrary
HTML and script code, which will be executed in a user's browser session in the
context of an affected site when the malicious data is being viewed.

Affected Software/OS:
Simple Invoices version 2011.1 and prior

Solution:
Upgrade to Simple Invoices version 2012-1 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Querverweis: BugTraq ID: 56882
Common Vulnerability Exposure (CVE) ID: CVE-2012-4932
Bugtraq: 20121209 SimpleInvoices 2011.1 Cross-Site-Scripting (XSS) Vulnerabilities CVE-2012-4932 (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2012-12/0074.html
CopyrightCopyright (C) 2012 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.