Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9...
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters in (d) admin/navigation/do_new_item.php; the (5) new_menuname parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name, and url parameters to (f) admin/pages/do_new_page.php, probably involving the Title or textarea field as reachable through admin/pages/new_page.php. NOTE: the original disclosure does not precisely state which vectors are associated with SQL injection versus XSS.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-4523
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/38444
- http://osvdb.org/38448
- http://www.securityfocus.com/archive/1/477320/100/0/threaded
- http://osvdb.org/38446
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36179
- http://www.securityfocus.com/bid/25406
- http://securityreason.com/securityalert/3058
- http://osvdb.org/38449
- http://osvdb.org/38447
- http://osvdb.org/38445
More from ripe website manager
View All →Affected Vendor
ripe website manager
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.