DB-Central CMS Search Cross-Site Scripting Vulnerability
BID:20622
Info
DB-Central CMS Search Cross-Site Scripting Vulnerability
| Bugtraq ID: | 20622 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 19 2006 12:00AM |
| Updated: | Nov 28 2006 06:50PM |
| Credit: | landseer is credited with the discovery of this vulnerability. |
| Vulnerable: |
db-central Enterprise CMS 0 db-central CMS 0 |
| Not Vulnerable: | |
Discussion
DB-Central CMS Search Cross-Site Scripting Vulnerability
db-central CMS is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
db-central CMS is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
DB-Central CMS Search Cross-Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
DB-Central CMS Search Cross-Site Scripting Vulnerability
Solution:
The vendor has released an update to address this issue. Please contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
The vendor has released an update to address this issue. Please contact the vendor for details on obtaining and applying the appropriate updates.
References
DB-Central CMS Search Cross-Site Scripting Vulnerability
References:
References:
- db-central Homepage (db-central)