|
[Japanese]
|
JVNDB-2005-000779
|
Hiki cross-site scripting vulnerability
|
Hiki, a Wiki clone from the Hiki development team, contains a cross-site scripting vulnerability.
|
Base Metrics:
4.3 (Medium)
[IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
Hiki Development Team
|
A remote attacker could create a content containing attacking code and take over a session by stealing the session ID of the user who logged into the system. If the user logged into the system as the administrator, the remote attacker could manipulate configurations.
|
|
Hiki Development Team
|
- JVN : JVN#38138980
- National Vulnerability Database (NVD) : CVE-2005-2803
- Common Vulnerabilities and Exposures (CVE) : CVE-2005-2803
- SecurityFocus : 15021
|
[2008/05/21]
Web page published
|
|
| 2005/08/04 |
| 2008/05/21 |
| 2008/05/21 |
|