Korean
<< Back
VID 21428
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The FuseTalk has a 'tombstone.cfm' script Cross-site Scripting Vulnerability.
FuseTalk is a Web-based forums package, developed by e-Zone Media. FuseTalk Enterprise Edition 2 and possibly other versions are vulnerable to cross-site scripting vulnerability, caused by a failure of the application to properly validate user-supplied input in the 'tombstone.cfm' script. A remote attacker could create a specially crafted URL link to the 'tombstone.cfm' script containing malicious script code in 'ProfileID' variable, and then could persuade a target user to click it. Once the URL is clicked, the embedded codes would be executed in the victim's Web browser. A remote attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

* References:
http://www.osvdb.org/displayvuln.php?osvdb_id=10752
http://securitytracker.com/alerts/2004/Oct/1011663.html

* Platforms Affected:
e-Zone Media, Inc., FuseTalk Enterprise Edition 2
Any operating system Any version
Recommendation No upgrade or patch available as of November 2004.

Upgrade to the new version of FusteTalk, when new version fixed this problem becomes available from the FusteTalk Web Site at http://www.fusetalk.com/
Related URL (CVE)
Related URL 11407 (SecurityFocus)
Related URL 17706 (ISS)