[Japanese] | |
JVNDB-2007-000225 | |
NewsGlue and Ikinari Jijyoutsuu arbitrary script execution vulnerability | |
Overview | |
NewsGlue and Ikinari Jijyoutsuu are RSS readers. An arbitrary script embedded in RSS feeds could be executed in either of the RSS readers, as they fail to handle the output of RSS information properly. | |
CVSS Severity (What is CVSS?) | |
CVSS V2 Severity:
Base Metrics 6.4 (Medium) [IPA Score]
| |
Affected Products | |
| |
Glue Software Corporation | |
| |
Impact | |
An arbitrary script could be executed in NewsGlue or Ikinari Jijyoutsuu. Arbitrary files on client PCs could be accessed by an attacker. | |
Solution | |
| |
Vendor Information | |
Glue Software Corporation | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2007/03/22 |
Date First Published | 2008/05/21 |
Date Last Updated | 2008/05/21 |