Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [KAPDA::#30] - CuteNews1.4.1 Cross_Site_Scripting Vulnerability |
|---|---|
| Date: | 4 Mar 2006 10:28:11 -0000 |
[KAPDA::#30] - CuteNews1.4.1 Cross_Site_Scripting Vulnerability KAPDA New advisory Vulnerable products : CuteNews1.4.1 Vendor: www.cutephp.com Risk: Low Vulnerabilities: Cross_Site_Scripting Discoverd by Roozbeh Afrasiabi and imei addmimistrator roozbeh_afrasiabi[at]yahoo[dot]com www.kapda.ir www.persiax.com Date : -------------------- Found : N/A Vendor Contacted : N/A About : -------------------- "Cute news is a powerful and easy for using news management system that use flat files to store its database. It supports comments, archives, search function, image uploading,backup function, IP banning, flood protection ..." (from cutephp.org) Vulnerability: -------------------- Cross_Site_Scripting : CuteNews is affected by a cross-site scripting vulnerability.This issue is due to the failure of the application to properly sanitize user- supplied input. As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of an unsuspecting user when followed. Detail and PoC : -------------------- please view original advisory for more info Solution : -------------------- N/A Original Advisory : -------------------- http://kapda.ir/advisory-277.html Credit : -------------------- Discoverd by Roozbeh Afrasiabi and imei addmimistrator roozbeh_afrasiabi@yahoo.com Kapda Security Science Researchers Insitute www.kapda.ir www.persiax.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Pixel Post Multiple Vulnerabilities, paisterist . nst |
|---|---|
| Next by Date: | PHP-Stats <= 0.1.9.1 remote commands execution, rgod |
| Previous by Thread: | Pixel Post Multiple Vulnerabilities, paisterist . nst |
| Next by Thread: | PHP-Stats <= 0.1.9.1 remote commands execution, rgod |
| Indexes: | [Date] [Thread] [Top] [All Lists] |