Search:     Advanced search
server monitoring

GuppY pg Parameter Vulnerability

Article ID: 19942
Last updated: 27 Jan, 2009
Views: 377
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

GuppY pg Parameter Vulnerability

(C) 2005 Josh Zlatin-Amishav

FamilyCGI abuses : XSS
Plugin ID19942
Bugtraq ID14752
14984
CVE IDCVE-2005-2853

Description:

Synopsis :

The remote web server contains a PHP script that is prone to cross-site
scripting and possibly directory traversal attacks.

Description :

The remote host is running GuppY / EasyGuppY, a CMS written in PHP.

The version of Guppy / EasyGuppY installed on the remote host fails to
sanitize user-supplied input to the pg field in the printfaq.php
script. An attacker can exploit this flaw to launch cross-site
scripting and possibly directory traversal attacks against the affected
application.

See also :

http://archives.neohapsis.com/archives/bugtraq/2005-09/0362.html

Solution :

Upgrade to version 4.5.6a or later.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N)
This article was:   Helpful | Not Helpful
Prev   Next
FTP     ASP-DEv XM Forum post.asp IMG Tag XSS