Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.80052
Kategorie:Web application abuses
Titel:CuteNews search.php Cross-Site Scripting Vulnerability
Zusammenfassung:The remote web server contains a PHP script that is affected by a; cross-site scripting issue.;; The version of Cutenews installed on the remote host fails to sanitize input to the 'search.php' script before; using it to generate dynamic HTML to be returned to the user. An unauthenticated attacker can exploit this issue; to execute a cross-site scripting attack.;; This version of Cutenews is also likely affected by other associated issues.
Beschreibung:Summary:
The remote web server contains a PHP script that is affected by a
cross-site scripting issue.

The version of Cutenews installed on the remote host fails to sanitize input to the 'search.php' script before
using it to generate dynamic HTML to be returned to the user. An unauthenticated attacker can exploit this issue
to execute a cross-site scripting attack.

This version of Cutenews is also likely affected by other associated issues.

Solution:
Update to the latest version.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Querverweis: BugTraq ID: 21233
CopyrightCopyright (C) 2008 Justin Seitz

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.