JVN#23563149
KENT-WEB ACCESS REPORT vulnerable to cross-site scripting
Overview
ACCESS REPORT provided by KENT-WEB contains a cross-site scripting vulnerability.
Products Affected
- ACCESS REPORT v5.02 and earlier
Description
ACCESS REPORT provided by KENT-WEB is a software to analyze web access logs. ACCESS REPORT contains a cross-site scripting vulnerability. This is caused by a particular method in which tags are embedded into the web page.
Note that this vulnerability is different from JVN#68830017.
Impact
An arbitrary script may be executed on the user's web browser.
Solution
Update the Software
Update to the latest version and modify the particular method in which tags are embedded into the web page, according to the information provided by the developer.
Vendor Status
Vendor | Link |
WebCreate Ltd | ACCESS REPORT (Japanese only) |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Analyzed on 2012.12.06
Measures | Conditions | Severity |
---|---|---|
Access Required | can be attacked over the Internet using packets |
|
Authentication | anonymous or no authentication (IP addresses do not count) |
|
User Interaction Required | the vulnerability can be exploited without an honest user taking any action |
|
Exploit Complexity | some expertise and/or luck required (most buffer overflows, guessing correctly in small space, expertise in Windows function calls) |
|
Credit
Masahiro YAMADA reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2012-5176 |
JVN iPedia |
JVNDB-2012-000107 |