Access Analyzer CGI Unspecified Cross Site Scripting Vulnerability
BID:34123
Info
Access Analyzer CGI Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 34123 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 16 2009 12:00AM |
| Updated: | Mar 16 2009 06:46PM |
| Credit: | JVN |
| Vulnerable: |
Futomi's CGI Cafe Access Analyzer CGI 3.8.1 |
| Not Vulnerable: |
Futomi's CGI Cafe Access Analyzer CGI 4.0 |
Discussion
Access Analyzer CGI Unspecified Cross Site Scripting Vulnerability
Access Analyzer CGI is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials.
Access Analyzer CGI 3.8.1 is vulnerable; other versions may also be affected.
Access Analyzer CGI is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials.
Access Analyzer CGI 3.8.1 is vulnerable; other versions may also be affected.
Exploit / POC
Access Analyzer CGI Unspecified Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Access Analyzer CGI Unspecified Cross Site Scripting Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for details.
Solution:
Vendor updates are available. Please contact the vendor for details.
References
Access Analyzer CGI Unspecified Cross Site Scripting Vulnerability
References:
References:
- Access Analyzer CGI Cross Site Scripting (Futomi CGI Cafe)
- Cross-site scripting vulnerability in Access Analyzer CGI Standard Version (Ver. (JVN)
- Vendor Homepage (Futomi CGI Cafe )