Published:2012/10/26  Last Updated:2012/10/26

JVN#00322303
Tokyo BBS vulnerable to cross-site scripting

Overview

Tokyo BBS contains a cross-site scripting vulnerability.

Products Affected

  • Tokyo BBS

Description

Tokyo BBS provided by Come on Girls Interface contains a cross-site scripting vulnerability.

Impact

An arbitrary script may be executed on the user's web browser.

Solution

Apply a patch
Apply the patch according to the information provided by the developer.
The developer is no longer distributing the product, but provided a patch to address this issue.

Vendor Status

Vendor Status Last Update Vendor Notes
Come on Girls Interface Vulnerable 2012/10/26 Come on Girls Interface website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Analyzed on 2012.10.26

Measures Conditions Severity
Access Required can be attacked over the Internet using packets
  • High
Authentication anonymous or no authentication (IP addresses do not count)
  • High
User Interaction Required the user must be convinced to take a standard action that does not feel harmful to most users, such as click on a link or view a file
  • Mid
Exploit Complexity the user must be convinced to take a difficult or suspicious action. If the honest user must have elevated privileges, they are likely to be more suspiciouse
  • High

Description of each analysis measures

Credit

Naohiko Tsuda reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2012-4019
JVN iPedia JVNDB-2012-000093