[Japanese]

JVNDB-2009-000030

a-News from Appleple vulnerable to cross-site scripting

Overview

a-News from Appleple contains a cross-site scripting vulnerability.

a-News, a web log system from Appleple, contains a cross-site scripting vulnerability.

Note that future releases and maintenance of a-News ended on May 14, 2009. The developer recommends users who wish to continue using a web log system to use a-blog.

According to the developer, a-Nikki, a-Column, a-Update and a-Link may also be vulnerable and is recommending users to switch to a-blog.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 4.3 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: None
  • Integrity Impact: Partial
  • Availability Impact: None
Affected Products


appleple inc.
  • a-News

Impact

An arbitrary script may be executed on the user's web browser.
Solution

[Do not use a-News]
As patches will not be provided, the developer recommends to discontinue the use of a-News and switch to a-blog.
Vendor Information

appleple inc.
CWE (What is CWE?)

  1. Cross-site Scripting(CWE-79) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2009-2292
References

  1. JVN : JVN#42927215
  2. National Vulnerability Database (NVD) : CVE-2009-2292
  3. Secunia Advisory : SA35171
  4. SecurityFocus : 35070
  5. ISS X-Force Database : 50679
  6. OPEN SOURCE VULNERABILITY DATABASE (OSVDB) : 54636
Revision History

  • [2009/05/22]
      Web page published