PT-2005-5584 · Namazu · Namazu
Published
1970-01-01
·
Updated
2017-07-11
·
CVE-2004-1318
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Namazu versions 2.0.13 and earlier
Description
The issue allows remote attackers to inject arbitrary HTML and web script, potentially leading to the disruption of protected information integrity. This can be achieved by exploiting a cross-site scripting (XSS) vulnerability in namazu.cgi, where a query starting with a tab ("%09") character prevents proper sanitization of the rest of the query. The vulnerability can be exploited remotely.
Recommendations
For Namazu versions 2.0.13 and earlier, consider disabling the namazu.cgi script until a patch is available to prevent exploitation of the XSS vulnerability. Restrict access to the affected script to minimize the risk of remote attackers injecting arbitrary HTML and web script.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Namazu