vendor:
Apache Open For Business (Apache OFBiz)
by:
Bonsai Information Security
7,5
CVSS
HIGH
Multiple Cross Site Scripting (XSS)
79
CWE
Product Name: Apache Open For Business (Apache OFBiz)
Affected Version From: Stable Version <= 9.04, SVN Revision <= 920371, Release Branch Candidate 4.0 Reviion <= 920371
Affected Version To: Stable Version <= 9.04, SVN Revision <= 920371, Release Branch Candidate 4.0 Reviion <= 920371
Patch Exists: Yes
Related CWE: CVE-2010-0432
CPE: a:apache:ofbiz
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2010
Multiple XSS in Apache OFBiz
Cross-Site Scripting attacks are a type of injection problem, in which malicious scripts are injected into the otherwise benign and trusted web sites. Cross-site scripting (XSS) attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Flaws that allow these attacks to succeed are quite widespread and occur anywhere a web application uses input from a user in the output it generates without validating or encoding it. This vulnerability can be exploited to force a logged in Administrator to run arbitrary SQL commands or create a new user with Full Privileges.
Mitigation:
Upgrade to Apache OFBiz 9.04.1 or later.