|
[Japanese]
|
JVNDB-2009-000001
|
MyNETS cross-site scripting vulnerability
|
MyNETS, an open source SNS software, contains a cross-site scripting vulnerability.
MyNETS from Usagi Project is an open source SNS (Social Networking Service) software. MyNETS contains a cross-site scripting vulnerability.
|
Base Metrics:
3.5 (Low)
[IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: Single Instance
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
|
Usagi Project
- MyNETS Ver1.2.0.1 and earlier
|
|
If a user views a specially crafted web page, an arbitrary script may be executed on the user's web browser.
|
[Update the Software]
Update to the latest version according to the information provided by the developers.
|
Usagi Project
|
- Cross-site Scripting(CWE-79) [IPA Evaluation]
|
- CVE-2009-0245
|
- JVN : JVN#36802959
- National Vulnerability Database (NVD) : CVE-2009-0245
- Secunia Advisory : SA33409
- SecurityFocus : 33145
- JVN iPedia (Japanese) : JVNDB-2009-000001
|
[2009/01/08]
Web page published
|