Korean
<< Back
VID 21449
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The PSNews software has a 'No' Parameter Cross-site Scripting Vulnerability.
PSNews is a freely available Content Management System (CMS) for Microsoft Windows operating systems. PSNews version 1.1 is vulnerable to cross-site scripting vulnerability, caused by a failure of the application to properly validate user-supplied input in certain parameters. A remote attacker could create a specially crafted URL link to the 'index.php' script containing malicious script code in 'no' parameter, and then could persuade a target user to click it. Once the URL is clicked, the embedded codes would be executed in the victim's Web browser. A remote attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

* References:
http://www.osvdb.org/displayvuln.php?osvdb_id=9786
http://securitytracker.com/alerts/2004/Sep/1011191.html

* Platforms Affected:
PSNews 1.1
Microsoft Windows Any version
Recommendation No upgrade or patch available as of June 2014.

Upgrade to the new version of PSNews, when new version fixed this problem becomes available from the PSNews Web Site at http://psnews.sourceforge.net/
Related URL CVE-2004-1665 (CVE)
Related URL 11124 (SecurityFocus)
Related URL 17302 (ISS)