|
Family: CGI abuses : XSS --> Category: infos
Zeroboard XSS Vulnerability Scan
Vulnerability Scan Summary Checks for Zeroboard XSS
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains several PHP scripts that are prone to
cross-site scripting attacks.
Description :
The remote host runs Zeroboard, a web BBS application popular in
Korea.
The remote version of this software is vulnerable to cross-site
scripting attacks due to a lack of sanitization of user-supplied data.
Successful exploitation of this issue may allow a possible hacker to execute
malicious script code in a user's browser within the context of the
affected web site.
See also :
http://www.securityfocus.com/archive/1/390933
Solution:
Upgrade to Zeroboard 4.1pl6 or later.
Threat Level:
Low / CVSS Base Score : 2
(AV:R/AC:L/Au:NR/C:P/A:N/I:N/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|