| Title | AJ Square AJ Article の index.php におけるクロスサイトスクリプティングの脆弱性 |
|---|---|
| Summary | AJ Square AJ Article の index.php には、クロスサイトスクリプティングの脆弱性が存在します。 |
| Possible impacts | 第三者により、update アクションの以下のパラメータを介して、任意の Web スクリプトまたは HTML を挿入される可能性があります。 (1) emailid (2) fname (3) lname (4) company (5) address1 (6) address2 (7) city (8) state (9) zipcode (10) phone (11) fax |
| Solution | ベンダ情報および参考情報を参照して適切な対策を実施してください。 |
| Publication Date | July 30, 2010, midnight |
| Registration Date | June 26, 2012, 4:19 p.m. |
| Last Update | June 26, 2012, 4:19 p.m. |
| CVSS2.0 : 警告 | |
| Score | 4.3 |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| aj square |
| aj article 3.0 |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2012年06月26日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) emailid, (2) fname, (3) lname, (4) company, (5) address1, (6) address2, (7) city, (8) state, (9) zipcode, (10) phone, and (11) fax parameters in an update action. NOTE: some of these details are obtained from third party information. |
|---|---|
| Publication Date | July 31, 2010, 5:30 a.m. |
| Registration Date | Jan. 29, 2021, 11:04 a.m. |
| Last Update | Nov. 21, 2024, 10:17 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:ajsquare:aj_article:3.0:*:*:*:*:*:*:* | |||||