| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.801741 |
| Kategorie: | Web application abuses |
| Titel: | Joomla 'Lyftenbloggie' Component Cross-Site Scripting Vulnerabilities |
| Zusammenfassung: | Check if Joomla Lyftenbloggie component is vulnerable for XSS attack |
| Beschreibung: | Overview: This host is running Joomla and is prone to Multiple Cross Site Scripting vulnerabilities. Vulnerability Insight: - Input passed via the 'tag' and 'category' parameters to 'index.php' (when 'option' is set to 'com_lyftenbloggie') is not properly sanitised before being returned to the user. Impact: Successful exploitation will let attackers to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. Impact Level: Application. Affected Software/OS: Joomla Lyftenbloggie component version 1.1.0 Fix: No solution or patch is available as of 10th February 2011. Information regarding this issue will be updated once the solution details are available. For updates refer to http://www.lyften.com/products/lyften-bloggie.html References: http://secunia.com/advisories/42677 http://packetstormsecurity.org/files/view/96761/joomlalyftenbloggie-xss.txt |
| Querverweis: |
BugTraq ID: 45468 Common Vulnerability Exposure (CVE) ID: CVE-2010-4718 http://packetstormsecurity.org/files/view/96761/joomlalyftenbloggie-xss.txt http://www.securityfocus.com/bid/45468 http://secunia.com/advisories/42677 |
| Copyright | Copyright (C) 2011 Greenbone Networks GmbH |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|