Nessus Plugin #17226

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

Verity Ultraseek search request XSS

Family:
CGI abuses
Category:
infos
Copyright:
This script is Copyright (C) 2005 David Maciejak
Summary:
Checks Verity Ultraseek search request XSS
Version:
$Revision: 1.1 $
Cve_id:
CAN-2005-0514
Bugtraq_id:
12617
Xrefs:
OSVDB:14045
Description:

The remote host runs Verity Ultraseek, an Enterprise Search Engine Software.

This version is vulnerable to cross-site scripting and remote script
injection due to a lack of sanitization of user-supplied data.
Successful exploitation of this issue may allow an attacker to execute
malicious script code on a vulnerable server.

Solution: Upgrade to version 5.3.3 or higher
Risk factor : Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.