Mayaa Character Encoding Cross-Site Scripting Vulnerability

TITLE:
Mayaa Character Encoding Cross-Site Scripting Vulnerability

SECUNIA ADVISORY ID:
SA26597

VERIFY ADVISORY:
http://secunia.com/advisories/26597/

CRITICAL:
Less critical

IMPACT:
Cross Site Scripting

WHERE:
From remote

SOFTWARE:
Mayaa 1.x
http://secunia.com/product/15492/

DESCRIPTION:
A vulnerability has been reported in Mayaa, which can be exploited by
malicious people to conduct cross-site scripting attacks.

Input passed in certain character encodings (e.g. UTF-7) is not
properly sanitised before being returned to the user. This can be
exploited to execute arbitrary HTML and script code in a user's
browser session in context of an affected site.

The vulnerability is reported in versions prior to 1.1.12.

SOLUTION:
Update to version 1.1.12 or later.

PROVIDED AND/OR DISCOVERED BY:
Fukumori

ORIGINAL ADVISORY:
Seasar:
http://mayaa.seasar.org/news/vulnerability20070816.html

JVN:
http://jvn.jp/jp/JVN%2338199598/index.html