JVN#57036470
Cross-site scripting vulnerability in leger (free edition)
Overview
leger (free edition) from 'AD2000' contains a cross-site scripting vulnerability.
Products Affected
- leger (free edition) May 22, 2009 edition (Ver.1.6.4) and earlier
Description
leger (free edition) from 'AD2000' is a software to manage conference room reservations. leger (free edition) contains a cross-site scripting vulnerability.
Impact
An arbitrary script may be executed on the user's web browser.
Solution
Update the Software
Update to the latest version according to the information provided by the vendor.
Vendor Status
Vendor | Link |
AD2000 |
WEB conference room reserveation free-sw leger (Japanese Only) |
References
JPCERT/CC Addendum
The vendor has reported that Ver. 1.6.4 released on May 22, 2009 did not address the vulnerability. The vulernability has been addressed in Ver. 1.6.5 released on May 26, 2009. For more information, refer to the vendor's website.Vulnerability Analysis by JPCERT/CC
Analyzed on 2009.05.22
Measures | Conditions | Severity |
---|---|---|
Access Required | Routed - can be attacked over the Internet using packets |
|
Authentication | None - anonymous or no authentication (IP addresses do not count) |
|
User Interaction Required | Simple - the user must be convinced to take a standard action that does not feel harmful to most users, such as click on a link or view a file |
|
Exploit Complexity | Low - little to no expertise and/or luck required to exploit (cross-site scripting) |
|
Credit
Tsuyoshi Ishibashi of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory | |
CPNI Advisory | |
TRnotes | |
CVE |
CVE-2009-2240 |
JVN iPedia |
JVNDB-2009-000031 |