Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.900372
Category:Web application abuses
Title:LightNEasy < 2.2.1 / 2.2.2 XSS Vulnerability
Summary:LightNEasy is prone to a cross-site scripting (XSS); vulnerability.
Description:Summary:
LightNEasy is prone to a cross-site scripting (XSS)
vulnerability.

Vulnerability Insight:
The following flaws exist:

- Input passed to the 'commentname', 'commentemail' and 'commentmessage' parameters when posting a
comment is not properly sanitised before being used.

- Input passed via the 'page' parameter to LightNEasy.php is not properly sanitised before being
used to read files and can be exploited by directory traversal attacks.

Vulnerability Impact:
Successful exploitation will allow attacker to inject arbitrary
HTML and script code, which will be executed when the malicious comment is viewed and disclose the
content of arbitrary files on an affected system.

Affected Software/OS:
LightNEasy version 2.2.1 and prior (no database) and LightNEasy
version 2.2.2 and prior (SQLite).

Solution:
Update to version 3.1 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-1937
BugTraq ID: 35229
http://www.securityfocus.com/bid/35229
Bugtraq: 20090603 [InterN0T] LightNEasy 2.2.2 - HTML Injection Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/504092/100/0/threaded
http://forum.intern0t.net/intern0t-advisories/1081-intern0t-lightneasy-2-2-2-html-injection-vulnerability.html
http://secunia.com/advisories/35354
CopyrightCopyright (C) 2009 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.