![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2011-2743 |
Description: | Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the action parameter to (1) the default URI or (2) includes/javascript.php, or the (3) title or (4) body parameter to admin/help.php. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.802311 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2011-2743 BugTraq ID: 48672 http://www.securityfocus.com/bid/48672 Bugtraq: 20110713 [oCERT-2011-001] Chyrp input sanitization errors (Google Search) http://www.securityfocus.com/archive/1/518890/100/0/threaded http://www.justanotherhacker.com/advisories/JAHx113.txt http://www.ocert.org/advisories/ocert-2011-001.html http://osvdb.org/73887 http://osvdb.org/73888 http://osvdb.org/73889 http://secunia.com/advisories/45184 http://securityreason.com/securityalert/8312 XForce ISS Database: chyrp-multiple-xss(68563) https://exchange.xforce.ibmcloud.com/vulnerabilities/68563 |