|
Family: CGI abuses --> Category: attack
mvnForum activatemember Cross-Site Scripting Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary Checks for an XSS flaw in mvnForum's activatemember script
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a Java application that is affected by
several cross-site scripting issues.
Description :
The remote host is running mvnForum, an open-source, forum application
based on Java J2EE.
The version of mvnForum installed on the remote host fails to sanitize
user-supplied input to the 'activatecode' and 'member' parameters of
the 'activatemember' script before using it to generate dynamic web
content. Successful exploitation of this issue may lead to the
execution of arbitrary HTML and script code in a user's browser within
the context of the affected application.
See also :
http://pridels.blogspot.com/2006/06/mvnforum-xss-vuln.html
Solution :
Unknown at this time.
Threat Level:
Low / CVSS Base Score : 2
(AV:R/AC:H/Au:NR/C:N/A:N/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|