Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.80052
Category:Web application abuses
Title:CuteNews search.php Cross-Site Scripting Vulnerability
Summary:The remote web server contains a PHP script that is affected by a; cross-site scripting issue.;; The version of Cutenews installed on the remote host fails to sanitize input to the 'search.php' script before; using it to generate dynamic HTML to be returned to the user. An unauthenticated attacker can exploit this issue; to execute a cross-site scripting attack.;; This version of Cutenews is also likely affected by other associated issues.
Description:Summary:
The remote web server contains a PHP script that is affected by a
cross-site scripting issue.

The version of Cutenews installed on the remote host fails to sanitize input to the 'search.php' script before
using it to generate dynamic HTML to be returned to the user. An unauthenticated attacker can exploit this issue
to execute a cross-site scripting attack.

This version of Cutenews is also likely affected by other associated issues.

Solution:
Update to the latest version.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: BugTraq ID: 21233
CopyrightCopyright (C) 2008 Justin Seitz

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.