Cit-e-Net Cit-e-Access CVE-2014-8753 Multiple Cross Site Scripting Vulnerabilities
BID:72614
CVE-2014-8753 |Info
Cit-e-Net Cit-e-Access CVE-2014-8753 Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 72614 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8753 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2015 12:00AM |
| Updated: | Feb 13 2015 12:00AM |
| Credit: | Wang Jing |
| Vulnerable: |
Cit-e-Net Cit-e-Access 6 |
| Not Vulnerable: | |
Discussion
Cit-e-Net Cit-e-Access CVE-2014-8753 Multiple Cross Site Scripting Vulnerabilities
Cit-e-Access is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Cit-e-Access 6 is vulnerable; other versions may also be affected.
Cit-e-Access is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Cit-e-Access 6 is vulnerable; other versions may also be affected.
References
Cit-e-Net Cit-e-Access CVE-2014-8753 Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Cit-e-Net Homepage (Cit-e-Net)
- CVE-2014-8753 CIT-E-NET MULTIPLE XSS (CROSS-SITE SCRIPTING) SECURITY VULNERABILI (Wang Jing)