PT-2009-2561 · Unica · Unica Affinium Campaign

Publicado

2009-08-26

·

Atualizado

2017-08-17

·

CVE-2008-7092

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Unica Affinium Campaign version 7.2.1.0.55
Description The issue allows remote attackers to inject arbitrary web script or HTML via various parameters in different actions and web pages, including url, PageName, and title parameters in a CustomBookMarkLink action, displayIcon parameter in the templates web page, crafted input to the listener server, and several id and other parameters in various actions and web pages. This can be achieved through Javascript events and crafted input.
Recommendations For Unica Affinium Campaign version 7.2.1.0.55, consider disabling the CustomBookMarkLink action and restricting access to the templates web page until a patch is available. Avoid using the url, PageName, title, displayIcon, id, function, sessionID, Frame, and affiniumUserName parameters in the affected actions and web pages until the issue is resolved. Restrict access to the listener server and the affected web pages to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-7092

Produtos afetados

Unica Affinium Campaign