Nessus Plugin #15480

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

Xoops viewtopic.php Cross Site Scripting Vulnerability

Family:
CGI abuses : XSS
Category:
infos
Copyright:
This script is Copyright (C) 2004 David Maciejak
Summary:
Detect Xoops viewtopic.php XSS
Version:
$Revision: 1.2 $
Cve_id:
-
Bugtraq_id:
9497
Xrefs:
-
Description:

The remote host is hosting the XOOPS CGI suite.

The weblinks module of XOOPS contains a file named 'viewtopic.php'
in /modules/newbb/ directory. The code of the module insufficently
filters out user provided data. The URL parameter used by 'viewtopic.php'
can be used to insert malicious HTML and/or JavaScript in to the web
page.

Solution : Upgrade to the latest version of XOOPS
Risk factor : Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.