|
|
|
|
|
|
|
| |
Lyris ListManager read/search/results words Parameter XSS |
|
| This script is Copyright (C) 2008-2010 Tenable Network Security, Inc. |
|
|
| Family | CGI abuses : XSS |
| Nessus Plugin ID | 33219 (listmanager_words_xss.nasl) |
| Bugtraq ID | 29761
|
| CVE ID | CVE-2008-2923
|
|
| Description: |
Synopsis :
The remote web server is affected by a cross-site scripting
vulnerability.
Description :
The remote host is running ListManager, a web-based commercial mailing
list management application from Lyris.
The version of ListManager installed on the remote host fails to
sanitize user input to the 'words' parameter of the
'read/search/results' script before including it in dynamic HTML
output. An attacker may be able to leverage this issue to inject
arbitrary HTML and script code into a user's browser to be executed
within the security context of the affected site.
See also :
http://holisticinfosec.org/content/view/71/45/
Solution :
Unknown at this time.
Risk factor :
Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
|
|
|
|
|
|