|
[Japanese]
|
JVNDB-2004-000554
|
Namazu cross-site scripting vulnerability
|
Namazu is vulnerable to cross-site scripting due to a problem in namazu.cgi. If an illegal character is specified in a string search of namazu.cgi, the subsequent characters are not processed properly.
|
Base Metrics:
4.3 (Medium)
[IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
|
Namazu Project.
- Namazu 2.0.13 and earlier
MIRACLE LINUX CORPORATION
- MIRACLE LINUX V2.0
- MIRACLE LINUX V2.1
- MIRACLE LINUX V3.0
|
|
All sites that use namazu.cgi for search processing on websites are vulnerable to cross-site scripting that allows an attacker to falsify web pages or steal cookie information.
|
|
Namazu Project.
MIRACLE LINUX CORPORATION
- MIRACLE LINUX Update Information : namazu
|
|
- CVE-2004-1318
|
- JVN : JVN#904429FE
- National Vulnerability Database (NVD) : CVE-2004-1318
- Secunia Advisory : SA13600
- SecurityFocus : 12053
|
[2008/05/21]
Web page published
|