vendor:
Zend Server
by:
Luigi Auriemma
8,8
CVSS
HIGH
Cross-site Scripting
79
CWE
Product Name: Zend Server
Affected Version From: Zend Server 5.6.0
Affected Version To: Zend Server 5.6.0
Patch Exists: YES
Related CWE: CVE-2011-4153
CPE: cpe:a:zend_technologies:zend_server:5.6.0
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-1045/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2011-4153/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2011-4153/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2012-0781/, https://www.rapid7.com/db/vulnerabilities/hpsmh-cve-2011-4153/, https://www.rapid7.com/db/vulnerabilities/php-cve-2011-4153/, https://www.rapid7.com/db/vulnerabilities/php-cve-2012-0781/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2011-4153/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2012-0781/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-1047/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-1046/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2011
Zend Server 5.6.0 Multiple Remote Script Insertion Vulnerabilities
An attacker can exploit these vulnerabilities by enticing an authenticated user to follow a malicious link. The malicious link contains a crafted URL with malicious script code in the vulnerable parameters. When the user visits the malicious link, the malicious script code will be stored in the vulnerable parameters and will be executed in the user's browser session in context of the affected site.
Mitigation:
Upgrade to Zend Server 5.6.1 or later.