| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.16058 |
| Category: | Web application abuses |
| Title: | YaCy Peer-To-Peer Search Engine XSS |
| Summary: | Checks for YaCy Peer-To-Peer Search Engine XSS |
| Description: | Synopsis : The remote host contains a peer-to-peer search engine that is prone to cross-site scripting attacks. Description : The remote host runs YaCy, a peer-to-peer distributed web search engine and caching web proxy. The remote version of this software is vulnerable to multiple cross-site scripting due to a lack of sanitization of user-supplied data. Successful exploitation of this issue may allow an attacker to use the remote server to perform an attack against a third-party user. See also : http://www.securityfocus.com/archive/1/385453 Solution: Upgrade to YaCy 0.32 or later. |
| Cross-Ref: |
BugTraq ID: 12104 Common Vulnerability Exposure (CVE) ID: CVE-2004-2651 Bugtraq: 20041224 XSS in yacy 0.31 (Google Search) http://archives.neohapsis.com/archives/bugtraq/2004-12/0413.html http://www.securityfocus.com/bid/12104 http://www.osvdb.org/12629 http://www.osvdb.org/12630 http://securitytracker.com/id?1012686 XForce ISS Database: yacy-index-xss(18688) http://xforce.iss.net/xforce/xfdb/18688 XForce ISS Database: yacy-wiki-xss(18690) http://xforce.iss.net/xforce/xfdb/18690 |
| Copyright | This script is Copyright (C) 2004 David Maciejak |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|