[Japanese]

JVNDB-2008-000012

Cross-site scripting vulnerability in multiple Tor World CGI scripts

Overview

Multiple Tor World CGI scripts contain a cross-site scripting vulnerability.

Tor World provides CGI scripts for implementing search engines, message boards, and other tools. Multiple Tor World CGI scripts contain a cross-site scripting vulnerability.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 4.3 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None
Affected Products


Tor World
  • Com Vote Ver 1.2 and earlier
  • i-Navigator Ver 4.0
  • Interactive BBS Ver 1.3 and earlier
  • Mobile Frontier Ver 2.1 and earlier
  • Simple BBS Ver 1.3 and earlier
  • Simple Vote Ver 1.1 and earlier
  • Tor Board Ver 1.1 and earlier
  • Tor News Ver 1.21 and earlier
  • Tor Search Ver 1.1 and earlier
  • Tor Diary (Kyou-No Hitokoto) Ver 1.5 and earlier

Impact

An arbitrary script can be executed on the user's web browser.
Solution

[Update the Software]
Apply the latest update provided by the vendor.
Vendor Information

Tor World
CWE (What is CWE?)

  1. Cross-site Scripting(CWE-79) [NVD Evaluation]
CVE (What is CVE?)

  1. CVE-2008-0917
References

  1. JVN : JVN#54593414
  2. National Vulnerability Database (NVD) : CVE-2008-0917
  3. Secunia Advisory : SA29039
  4. SecurityFocus : 27919
Revision History

  • [2008/05/21]
      Web page published