Share360 Cross-Site Scripting Vulnerabilities
BID:5151
Info
Share360 Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 5151 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 03 2002 12:00AM |
| Updated: | Jul 03 2002 12:00AM |
| Credit: | This issue was announced in the release notes for the product. |
| Vulnerable: |
Cybozu Share360 1.1 |
| Not Vulnerable: |
Cybozu Share360 1.2 |
Discussion
Share360 Cross-Site Scripting Vulnerabilities
Share360 is prone to cross-site scripting attacks. It is possible for an attacker to exploit this issue via a maliciously crafted link which includes arbitrary HTML or script code. When the malicious link is clicked, the attacker's script code will executed in the browser of the web user who has clicked the link, in the security context of the site hosting the Share360 software.
This issue is reported to be present in a number of the Share360 applications.
Share360 is prone to cross-site scripting attacks. It is possible for an attacker to exploit this issue via a maliciously crafted link which includes arbitrary HTML or script code. When the malicious link is clicked, the attacker's script code will executed in the browser of the web user who has clicked the link, in the security context of the site hosting the Share360 software.
This issue is reported to be present in a number of the Share360 applications.
Exploit / POC
Share360 Cross-Site Scripting Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Share360 Cross-Site Scripting Vulnerabilities
Solution:
The vendor has addressed this issue in version 1.2. Those affected by this issue are advised to upgrade.
Solution:
The vendor has addressed this issue in version 1.2. Those affected by this issue are advised to upgrade.