Nucleus CMS EUC-JP Cross-Site Scripting Vulnerability
BID:31590
Info
Nucleus CMS EUC-JP Cross-Site Scripting Vulnerability
| Bugtraq ID: | 31590 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4446 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2008 12:00AM |
| Updated: | Apr 16 2015 05:53PM |
| Credit: | Gaku Mochizuki of Mitsui Bussan Secure Directions, Ltd. |
| Vulnerable: |
Nucleus CMS Nucleus CMS 3.32 SP1 EUC-JP |
| Not Vulnerable: |
Nucleus CMS Nucleus CMS 3.32 SP2 EUC-JP |
Discussion
Nucleus CMS EUC-JP Cross-Site Scripting Vulnerability
Nucleus CMS is prone to an unspecified cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The issue affects Nucleus 3.31 SP1 EUC-JP. The English versions and Nucleus UTF-8 Japanese Edition are not affected.
NOTE: Reports indicate that this issue occurs only when using Internet Explorer.
Nucleus CMS is prone to an unspecified cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
The issue affects Nucleus 3.31 SP1 EUC-JP. The English versions and Nucleus UTF-8 Japanese Edition are not affected.
NOTE: Reports indicate that this issue occurs only when using Internet Explorer.
Exploit / POC
Nucleus CMS EUC-JP Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Nucleus CMS EUC-JP Cross-Site Scripting Vulnerability
Solution:
Nucleus CMS 3.31 SP2 EUC-JP has been released to address this issue. Please see the references for more information.
Solution:
Nucleus CMS 3.31 SP2 EUC-JP has been released to address this issue. Please see the references for more information.
References
Nucleus CMS EUC-JP Cross-Site Scripting Vulnerability
References:
References: