PT-2005-5584 · Namazu · Namazu

Published

1970-01-01

·

Updated

2017-07-11

·

CVE-2004-1318

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Namazu versions 2.0.13 and earlier
Description The issue allows remote attackers to inject arbitrary HTML and web script, potentially leading to the disruption of protected information integrity. This can be achieved by exploiting a cross-site scripting (XSS) vulnerability in namazu.cgi, where a query starting with a tab ("%09") character prevents proper sanitization of the rest of the query. The vulnerability can be exploited remotely.
Recommendations For Namazu versions 2.0.13 and earlier, consider disabling the namazu.cgi script until a patch is available to prevent exploitation of the XSS vulnerability. Restrict access to the affected script to minimize the risk of remote attackers injecting arbitrary HTML and web script.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03075
BDU:2015-03076
CVE-2004-1318
DSA-627-1

Affected Products

Namazu