Vulnerabilities > CVE-2004-2550 - Unspecified vulnerability in Xperience Sandsurfer
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN xperience
nessus
Summary
Multiple cross-site scripting (XSS) vulnerabilities in unspecified Perl scripts in SandSurfer before 1.7.1 allow remote attackers to inject arbitrary web script or HTML, which is later executed by a target who views reports containing the injected data.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Nessus
NASL family | CGI abuses : XSS |
NASL id | SANDSURFER_XSS.NASL |
description | The remote host is running SandSurfer, a web-based time keeping application. A vulnerability has been disclosed in all versions of this software, up to version 1.7.0 (included) which may allow an attacker to use it to perform cross-site scripting attacks against third-party users. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 12087 |
published | 2004-03-04 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/12087 |
title | SandSurfer < 1.7.1 XSS |
code |
|
References
- http://secunia.com/advisories/11028
- http://secunia.com/advisories/11028
- http://sourceforge.net/forum/forum.php?forum_id=356882
- http://sourceforge.net/forum/forum.php?forum_id=356882
- http://www.osvdb.org/4132
- http://www.osvdb.org/4132
- http://www.securityfocus.com/bid/9801
- http://www.securityfocus.com/bid/9801
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15377
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15377