HIO-2008-0311 Savvy Content Manager XSS

Savvy Content Manager contains a flaw that allows a remote cross site scripting attack.  This flaw exists because the application does not validate the "searchterms" variable upon submission to the searchresults.cfm, search_results.cfm, or search_results/index.cfm scripts.  This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.

References:

BID: 28200

CVE-2008-1306

OSVDB: 42705

OSVDB: 42706

OSVDB: 42707

Secunia: 29298

SecWatch

Vendor Solution

Additional information