Search:     Advanced search
server monitoring

dasBlog HTML Injection Vulnerability

Article ID: 14639
Last updated: 27 Jan, 2009
Views: 413
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

dasBlog HTML Injection Vulnerability

This script is Copyright (C) 2004 Tenable Network Security

FamilyCGI abuses : XSS
Plugin ID14639
Bugtraq ID11086
CVE IDCVE-2004-1657

Description:

The remote host is running dasBlog, a .NET blog system. It is reported that
versions up to and including 1.6.0 are vulnerable to an HTML injection issue.
The application does not sanitize the Referer and User-Agent HTTP headers.
An attacker may use this weakness to include malicious code in the Activity
and Events Viewer which may be executed by an administrator displaying this
page.

Solution : Upgrade to the latest version of this software
Risk factor : Medium
This article was:   Helpful | Not Helpful
Prev   Next
WEBppliance ocw_login_username Parameter Cross-Site Scripting...     JAWS HTML injection vulnerabilities