Search:     Advanced search
server monitoring

JAWS HTML injection vulnerabilities

Article ID: 19394
Last updated: 27 Jan, 2009
Views: 446
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

JAWS HTML injection vulnerabilities

Copyright (C) 2005 Josh Zlatin-Amishav

FamilyCGI abuses : XSS
Plugin ID19394
Bugtraq ID13254
13796
CVE IDCVE-2005-1231
CVE-2005-1800

Description:

The remote host is running JAWS, a content management system written in PHP.

The remote version of this software does not perform a proper
validation of user-supplied input to several variables used in the
GlossaryModel.php script, and is therefore vulnerable to cross-site
scripting attacks.

See also : http://seclists.org/lists/fulldisclosure/2005/Apr/0416.html
http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/034354.html
Solution : Upgrade to JAWS 0.5.2 or later.
Risk factor : Medium
This article was:   Helpful | Not Helpful
Prev   Next
dasBlog HTML Injection Vulnerability     Adobe Flex History Management Cross-Site Scripting