|
|
| |
| JSPWiki is "one of famous wiki web applications". A vulnerability in the JSPWiki's is caused due to an input validation flaw, the vulnerability allows remote attackers to initiate a cross site scripting attack. |
| |
Credit:
The information has been provided by STG Security Advisory.
|
| |
Vulnerable Systems:
* JSPWiki version 2.1.120-cvs
Exploit:
http://[victim]/Search.jsp?query=%3Cscript%3E%3C/script%3E&ok=Find%21
Vendor response:
2004-10-01 - Vulnerability found.
2004-10-27 - JSPWiki developer notified.
2004-11-22 - Official release.
|
|
|