PT-2009-3178 · Sajax · Sajax

Published

2009-02-11

·

Updated

2009-02-12

·

CVE-2009-0525

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Sajax version 0.12
Description A cross-site scripting issue exists due to improper handling of the URL parameter in the sajax get common js function within php/Sajax.php. This allows remote attackers to inject arbitrary web script or HTML, particularly when using browsers that do not URL-encode requests.
Recommendations For Sajax version 0.12, consider disabling the sajax get common js function as a temporary workaround until a patch is available. Restrict access to the php/Sajax.php file to minimize the risk of exploitation. Avoid using the URL parameter in affected browsers until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0525

Affected Products

Sajax