[Japanese] | |
JVNDB-2007-000074 | |
phpAdsNew cross-site scripting vulnerability | |
Overview | |
phpAdsNew, an open source web advertising management system, contains a cross-site scripting vulnerability. | |
CVSS Severity (What is CVSS?) | |
CVSS V2 Severity:
Base Metrics 4.3 (Medium) [IPA Score]
| |
Affected Products | |
| |
Openads | |
| |
Impact | |
An arbitrary script may be executed on the the user's web browser if the user logged into phpAdsNew as the administrator. This may allow cookie information to be leaked or displayed contents to be falsified. | |
Solution | |
| |
Vendor Information | |
Openads | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2007/01/22 |
Date First Published | 2008/05/21 |
Date Last Updated | 2008/05/21 |