vendor:
JAKCMS PRO
by:
Saif El-Sherei
7.5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: JAKCMS PRO
Affected Version From: JAKCMS PRO 2.0 RC5
Affected Version To: JAKCMS PRO 2.0 RC5 and probably earlier versions
Patch Exists: YES
Related CWE: N/A
CPE: 2.0:rc5:jakcms_pro
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Firefox 3.0.15, IE 8
2011
JAKCMS 2.0 PRO RC5 stored XSS via useragent HTTP header Injection
An attacker can exploit this vulnerability since using an intercepting proxy, where an attacker can modify the 'user-agent HTTP header' the Header is displayed and stored unsanitized in the admin logs on failed and successful logins.
Mitigation:
Ensure that user-agent HTTP headers are sanitized before being stored in the admin logs.