Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.19587
Kategorie:Web application abuses
Titel:ATutor Cross Site Scripting Vulnerability
Zusammenfassung:The remote version of ATutor is prone to cross-site scripting; attacks due to its failure to sanitize user-supplied input.
Beschreibung:Summary:
The remote version of ATutor is prone to cross-site scripting
attacks due to its failure to sanitize user-supplied input.

Solution:
No known solution was made available for at least one year since the
disclosure of this vulnerability. Likely none will be provided anymore. General solution options are to
upgrade to a newer release, disable respective features, remove the product or replace the product by another
one.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Querverweis: BugTraq ID: 14598
Common Vulnerability Exposure (CVE) ID: CVE-2005-2649
http://www.securityfocus.com/bid/14598
Bugtraq: 20050818 ATutor 1.5.1 and prior multiple XSS Vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/408521
http://secunia.com/advisories/16496
XForce ISS Database: atutor-login-search-xss(21910)
https://exchange.xforce.ibmcloud.com/vulnerabilities/21910
CopyrightCopyright (C) 2005 Josh Zlatin-Amishav

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.