|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com |
|
|
Home SecurityAlert Database |
|
|
Topic : | Namo DeepSearch 4.5 Cross-Site Scripting Vulnerability
|
SecurityAlert : 1156
CVE : CVE-2006-3264
SecurityRisk : Low (About)
Remote Exploit : Yes
Local Exploit : No
Exploit Available : Yes
Credit : Kil13r
Published : 29.06.2006
Affected Software : | Namo DeepSearch 4.5 or earlier |
 Advisory Content : Title:
[Kil13r-SA-20060622-2] Namo DeepSearch 4.5 Cross-Site Scripting
Vulnerability
Author:
Kil13r - http://www.kil13r.info/
Local / Remote:
Remote
Timeline:
2006/06/21 - Discovery
2006/06/21 - Vendor notification
2006/06/21 - Vendor response
2006/06/22 - Release
Affected version:
Namo DeepSearch 4.5 or earlier
Not affected version:
Description:
Namo DeepSearch is search engine solution, but that has vulnerability.
It can run arbitrary Javascript code by end user in search engine.
If victim execute arbitrary Javascript code, attacker can steal victim's
cookie.
Edit Namo DeepSearch HTML template to workaround.
Proof of Concept code:
None
Proof of Concept example:
http://www.victim.com/cgi-bin/mclient.cgi?p="><script>alert(String.fromC
harCode(88,83,83,32,53580,49828,53944))</script>
Proof of Concept screenshot:
http://www.kil13r.info/sa/xss/deepsearchxss.jpg
-
Igitur qui desiderat pacem, praeparet bellum.
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|