|
|
|
![]() |
Vulnerability Note VU#664422PhpWebSite contains multiple cross-site scripting vulnerabilitiesOverviewPhpWebSite contains multiple cross-site scripting vulnerabilities that may allow an attacker to execute arbitrary code on users' web browser.I. DescriptionPhpWebSite is an open-source web content management system. Certain PhpWebSite modules fail to properly filter URLs for malicious content. This may allow scripting code to be inserted into a URL and then executed within the users' web browser. The following PhpWebSite modules contain this vulnerability:
In addition, error pages generated by PhpWebSite are reported to be vulnerable. II. ImpactAn attacker may be able to execute arbitrary code in a guest or logged-in users' web browser with the privileges of that user.III. SolutionApply a Patch
Referenceshttp://www.gulftech.org/?node=research&article_id=00048-08312004 This vulnerability was publicly reported by GulfTech Security. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||