|
[Japanese]
|
JVNDB-2008-000071
|
MyNETS cross-site scripting vulnerability
|
MyNETS, an open source SNS software, contains a cross-site scripting vulnerability.
MyNETS from Usagi Project is an open source SNS (Social Networking Service) software. MyNETS contains a cross-site scripting vulnerability.
|
Base Metrics:
3.5 (Low)
[IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: Single Instance
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
Usagi Project
- MyNETS Ver1.2.0 and earlier
|
If a user views a specially crafted web page, an arbitrary script may be executed on the user's web browser. As a result, user information may be disclosed or a user may be directed to an unintended site.
|
[Update the Software]
Update to the latest version according to the information provided by the developers.
|
Usagi Project
|
- JVN : JVN#53267766
- National Vulnerability Database (NVD) : CVE-2008-4629
- Common Vulnerabilities and Exposures (CVE) : CVE-2008-4629
- Secunia Advisory : SA32348
- Common Weakness Enumeration (CWE) : Cross-site scripting (CWE-79) [IPA Evaluation]
- JVN iPedia (Japanese) : JVNDB-2008-000071
|
[2008/10/22]
Web page published
|
|
| 2008/10/20 |
| 2008/10/22 |
| 2008/10/22 |
|