ChamaCargo CVE-2013-4704 Unspecified Cross-Site Scripting Vulnerability
BID:62384
Info
ChamaCargo CVE-2013-4704 Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 62384 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4704 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2013 12:00AM |
| Updated: | Mar 19 2015 08:27AM |
| Credit: | Koki Takahashi of Keiji Takeda Lab, Keio University. |
| Vulnerable: |
ChamaNet Chamacargo 7.0000 ChamaNet Chamacargo 6.3300 |
| Not Vulnerable: | |
Discussion
ChamaCargo CVE-2013-4704 Unspecified Cross-Site Scripting Vulnerability
ChamaCargo is prone to an unspecified cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
ChamaCargo 7.0000 and prior are vulnerable.
ChamaCargo is prone to an unspecified cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
ChamaCargo 7.0000 and prior are vulnerable.
Exploit / POC
ChamaCargo CVE-2013-4704 Unspecified Cross-Site Scripting Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim to open a malicious URI.
Solution / Fix
ChamaCargo CVE-2013-4704 Unspecified Cross-Site Scripting Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
ChamaCargo CVE-2013-4704 Unspecified Cross-Site Scripting Vulnerability
References:
References:
- ChamaCargo Homepage (Chama.ne.jp)
- JVN#77455005 ChamaCargo vulnerable to cross-site scripting (JPCERT/CC and IPA)
- JVNDB-2013-000088 ChamaCargo vulnerable to cross-site scripting (IPA)