Mayaa Default Error Page Cross-Site Scripting Vulnerability
BID:33015
Info
Mayaa Default Error Page Cross-Site Scripting Vulnerability
| Bugtraq ID: | 33015 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5720 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 25 2008 12:00AM |
| Updated: | Dec 31 2008 11:31PM |
| Credit: | Tetsuo Nakamura of NEC Soft, Ltd. |
| Vulnerable: |
Mayaa Mayaa 1.1.22 Mayaa Mayaa 1.1.12 Mayaa Mayaa 1.1.11 |
| Not Vulnerable: | |
Discussion
Mayaa Default Error Page Cross-Site Scripting Vulnerability
Mayaa is prone a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected application. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Mayaa 1.1.22 and earlier are vulnerable.
Mayaa is prone a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected application. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Mayaa 1.1.22 and earlier are vulnerable.
Exploit / POC
Mayaa Default Error Page Cross-Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Mayaa Default Error Page Cross-Site Scripting Vulnerability
Solution:
Vendor patches are available. Contact the vendor for details.
Solution:
Vendor patches are available. Contact the vendor for details.
References
Mayaa Default Error Page Cross-Site Scripting Vulnerability
References:
References: