Tuesday 10 February 2015

CVE-2014-9559 SnipSnap XSS (Cross-Site Scripting) Security Vulnerabilities

computer-security-art


















Exploit Title: SnipSnap /snipsnap-search? query Parameter XSS
Product: SnipSnap
Vulnerable Versions: 0.5.2a 1.0b1 1.0b2
Tested Version: 0.5.2a 1.0b1 1.0b2
Advisory Publication: Jan 30, 2015
Latest Update: Jan 30, 2015
Vulnerability Type: Cross-Site Scripting [CWE-79]
CVE Reference: CVE-2014-9559
CVSS Severity (version 2.0):
CVSS v2 Base Score: 4.3 (MEDIUM) (AV:N/AC:M/Au:N/C:N/I:P/A:N) (legend)
Impact Subscore: 2.9
Exploitability Subscore: 8.6
Credit: Wang Jing [MAS, Nanyang Technological University (NTU), Singapore]


http://www.inzeed.com/kaleidoscope/xss-vulnerability/cve-2014-9559-snipsnap-xss-cross-site-scripting-security-vulnerabilities/

No comments:

Post a Comment