Nessus Plugin #17612

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

Interspire ArticleLive 2005 XSS Vulnerability

Family:
CGI abuses : XSS
Category:
attack
Copyright:
This script is Copyright (C) 2005 Noam Rathaus
Summary:
Checks for the presence of a ArticleLive XSS
Version:
$Revision: 1.1 $
Cve_id:
-
Bugtraq_id:
12879
Xrefs:
-
Description:

The remote host is running ArticleLive, a set of CGIs designed to simplify
the management of a news site.

Due to improper filtering done by the script 'newcomment' remote attacker
can cause the ArticleLive product to include arbitrary HTML and/or
JavaScript, and therefore use the remote host to perform cross-site
scripting attacks.

Solution : Upgrade to the newest version of this software
Risk factor: Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.