Korean
<< Back
VID 21326
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The PowerPortal installed on the Web server has multiple Cross-Site Scripting Vulnerabilities.
PowerPortal is a popular content management system for Unix-based platforms, written in PHP. PowerPortal version 1.x is vulnerable to cross-site scripting in 'modules.php', caused by improper filtering of user-supplied input. A remote attacker could create a specially crafted URL link containing malicious code in the id, search or files variable, and then could persuade a target user to click it. Once the URL is clicked, the embedded codes would be executed in the victim's Web browser. A remote attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

* References:
http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0905.html
http://securitytracker.com/alerts/2004/Jun/1010596.html

* Platforms Affected:
PowerPortal 1.x
Unix Any version
Recommendation No upgrade or patch available as of June 2014.. Contact to your vendor for this vulnerability.
Related URL CVE-2004-0663 (CVE)
Related URL 10622 (SecurityFocus)
Related URL 16528 (ISS)