|
HIO-2008-0311 Savvy Content Manager XSS |
|
|
|
|
Savvy Content Manager contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "searchterms" variable upon submission to the searchresults.cfm, search_results.cfm, or search_results/index.cfm scripts. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. References: BID: 28200 CVE-2008-1306 OSVDB: 42705 OSVDB: 42706 OSVDB: 42707 Secunia: 29298 SecWatch Vendor Solution
|