JVN#42927215
a-News from Appleple vulnerable to cross-site scripting
Overview
a-News from Appleple contains a cross-site scripting vulnerability.
Products Affected
- a-News
Description
a-News, a web log system from Appleple, contains a cross-site scripting vulnerability.
Note that future releases and maintenance of a-News ended on May 14, 2009. The developer recommends users who wish to continue using a web log system to use a-blog.
Impact
An arbitrary script may be executed on the user's web browser.
Solution
Do not use a-News
As patches will not be provided, the developer recommends to discontinue the use of a-News and switch to a-blog.
Vendor Status
References
JPCERT/CC Addendum
According to the developer, a-Nikki, a-Column, a-Update and a-Link may also be vulnerable and is recommending users to switch to a-blog.Vulnerability Analysis by JPCERT/CC
Analyzed on 2009.05.21
Measures | Conditions | Severity |
---|---|---|
Access Required | Routed - can be attacked over the Internet using packets |
|
Authentication | None - anonymous or no authentication (IP addresses do not count) |
|
User Interaction Required | Simple - the user must be convinced to take a standard action that does not feel harmful to most users, such as click on a link or view a file |
|
Exploit Complexity | Low - little to no expertise and/or luck required to exploit (cross-site scripting) |
|
Credit
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory | |
CPNI Advisory | |
TRnotes | |
CVE |
CVE-2009-2292 |
JVN iPedia |
JVNDB-2009-000030 |