vendor:
Seo Panel
by:
Mark Stanislav
7.5
CVSS
HIGH
Persistent XSS
79
CWE
Product Name: Seo Panel
Affected Version From: 2.2.2000
Affected Version To: 2.2.2000
Patch Exists: NO
Related CWE: CVE-2010-4331
CPE: a:seopanel:seo_panel
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2010
Seo Panel Cookie-Rendered Persistent XSS Vulnerability (CVE-2010-4331)
A vulnerability exists in 'Seo Panel' page rendering which allows for unfiltered, unencrypted content to be presented to a user through two different cookies. Alter the value of cookies called 'default_news' or 'sponsors' and then view a site page which includes controllers/index.ctrl.php or controllers/settings.ctrl.php that will render the cookies as they exist on the user's machine.
Mitigation:
Upgrade to a release > 2.2.0 when available or otherwise disable cookie rendering.