vendor:
Achievo
by:
Ryan Dewhurst
7.5
CVSS
HIGH
Multiple Cross Site Scripting (XSS)
79
CWE
Product Name: Achievo
Affected Version From: <= 1.3.4
Affected Version To: None
Patch Exists: Yes
Related CWE: CVE-2009-2733
CPE: achievo
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Web Application
2009
Multiple XSS in Achievo
Cross-Site Scripting attacks are a type of injection problem, in which malicious scripts are injected into the otherwise benign and trusted web sites. Cross-site scripting (XSS) attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Flaws that allow these attacks to succeed are quite widespread and occur anywhere a web application uses input from a user in the output it generates without validating or encoding it.
Mitigation:
Upgrade to the latest version of Achievo