vendor:
Digital Scribe
by:
Gjoko 'LiquidWorm' Krstic
8.8
CVSS
HIGH
Multiple POST XSS
79
CWE
Product Name: Digital Scribe
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: YES
Related CWE: N/A
CPE: 2.3:a:digital_scribe:digital_scribe:1.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN), Apache 2.2.14 (Win32), PHP 5.3.1, MySQL 5.1.41
2011
Digital Scribe 1.5 (register_form()) Multiple POST XSS Vulnerabilities
Digital Scribe suffers from multiple POST XSS vulnerabilities. Input thru the POST parameters 'title', 'last' and 'email' in register.php is not sanitized allowing the attacker to execute HTML code into user's browser session on the affected site.
Mitigation:
Vendor released patch.