Vulnerabilities > CVE-2004-2651 - Unspecified vulnerability in Michael Christen Yacy
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN michael-christen
nessus
Summary
Multiple cross-site scripting (XSS) vulnerabilities in YaCy before 0.32 allow remote attackers to inject arbitrary web script or HTML via the (1) urlmaskfilter parameter to index.html or the (2) page parameter to Wiki.html.
Vulnerable Configurations
Nessus
NASL family | CGI abuses : XSS |
NASL id | YACY_XSS.NASL |
description | The remote host runs YaCy, a peer-to-peer distributed web search engine and caching web proxy. The remote version of this software is vulnerable to multiple cross-site scripting due to a lack of sanitization of user-supplied data. Successful exploitation of this issue may allow an attacker to use the remote server to perform an attack against a third-party user. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 16058 |
published | 2004-12-28 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/16058 |
title | YaCy Peer-To-Peer Search Engine XSS |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2004-12/0413.html
- http://archives.neohapsis.com/archives/bugtraq/2004-12/0413.html
- http://securitytracker.com/id?1012686
- http://securitytracker.com/id?1012686
- http://www.osvdb.org/12629
- http://www.osvdb.org/12629
- http://www.osvdb.org/12630
- http://www.osvdb.org/12630
- http://www.securityfocus.com/bid/12104
- http://www.securityfocus.com/bid/12104
- http://www.yacy.net/yacy/News.html
- http://www.yacy.net/yacy/News.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18688
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18688
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18690
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18690