[Japanese]
|
JVNDB-2011-000015
|
Multiple Things CGI products vulnerable to cross-site scripting
|
Multiple CGI products provided by Things contain a cross-site scripting vulnerability.
BBS and BBS Thread provided by Things are bulletin board software. BBS and BBS Thread contain a cross-site scripting vulnerability.
Yuji Tounai of bogus.jp reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 4.3 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
Things
- BBS Thread version 2.0.2 and earlier
- BBS version 2.0.2 and earlier
|
|
An arbitrary script may be executed on the user's web browser.
|
[Update the software]
Update to the latest version according to the information provided by the developer.
This issue was resolved in the following versions:
BBS version 2.0.3
BBS Thread version 2.0.3
|
Things
|
- Cross-site Scripting(CWE-79) [IPA Evaluation]
|
- CVE-2011-0455
|
- JVN : JVN#20982938
- National Vulnerability Database (NVD) : CVE-2011-0455
- Secunia Advisory : SA43524
- SecurityFocus : 46638
- ISS X-Force Database : 65852
|
- [2011/03/02]
Web page published
|