[Japanese]
|
JVNDB-2008-000058
|
Multiple Tor World CGI scripts vulnerable to arbitrary script execution
|
Multiple Tor World CGI scripts contain a vulnerability which may allow an arbitrary script execution.
Tor World provides CGI scripts for implementing search engines, message boards, and other tools. Multiple Tor World CGI scripts contain a vulnerability which may allow an attacker to inject an arbitrary script into the web page which is generated by the affected product.
This vulnerability is different from JVN#54593414.
Yutaka Kokubu of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendor under the Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 2.6 (Low) [IPA Score]
- Access Vector: Network
- Access Complexity: High
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
Tor World
- Interactive BBS Ver1.57 and earlier
- Simple BBS Ver1.86 and earlier
- Topics BBS Ver1.11 and earlier
- Tor Board Ver1.3 and earlier
|
|
An arbitrary script may be executed on the user's web browser.
|
[Update the Software]
Apply the latest updates provided by the vendor.
|
Tor World
|
- Cross-site Scripting(CWE-79) [IPA Evaluation]
|
- CVE-2008-4076
|
- JVN : JVN#18616622
- National Vulnerability Database (NVD) : CVE-2008-4076
- SecurityFocus : 31105
- ISS X-Force Database : 45043
- JVN iPedia (Japanese) : JVNDB-2008-000058
|
- [2008/09/18]
Web page published
|