CONTENS Near Parameter Cross-Site Scripting Vulnerability
BID:15943
Info
CONTENS Near Parameter Cross-Site Scripting Vulnerability
| Bugtraq ID: | 15943 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-4388 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2005 12:00AM |
| Updated: | Mar 28 2008 03:59PM |
| Credit: | Discovered by rakstija r0t3d3Vil. |
| Vulnerable: |
CONTENS CONTENS 3.0 |
| Not Vulnerable: | |
Discussion
CONTENS Near Parameter Cross-Site Scripting Vulnerability
CONTENS is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
CONTENS is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
CONTENS Near Parameter Cross-Site Scripting Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
CONTENS Near Parameter Cross-Site Scripting Vulnerability
Solution:
The vendor has relesaed an update. Please contact the vendor for more information.
Solution:
The vendor has relesaed an update. Please contact the vendor for more information.
References
CONTENS Near Parameter Cross-Site Scripting Vulnerability
References:
References:
- CONTENS "search.cfm" Multiple Input Validation Vuln (rakstija r0t3d3Vil)
- CONTENS Home Page (CONTENS)