Mayaa Character Encoding Cross-Site Scripting Vulnerability
by Marianna Schmudlach - 8/27/07 2:33 PM
In Reply to: VULNERABILITIES \ FIXES - August 27, 2007 by Marianna Schmudlach
TITLE:
Mayaa Character Encoding Cross-Site Scripting Vulnerability
SECUNIA ADVISORY ID:
SA26597
VERIFY ADVISORY:
http://secunia.com/advisories/26597/
CRITICAL:
Less critical
IMPACT:
Cross Site Scripting
WHERE:
From remote
SOFTWARE:
Mayaa 1.x
http://secunia.com/product/15492/
DESCRIPTION:
A vulnerability has been reported in Mayaa, which can be exploited by
malicious people to conduct cross-site scripting attacks.
Input passed in certain character encodings (e.g. UTF-7) is not
properly sanitised before being returned to the user. This can be
exploited to execute arbitrary HTML and script code in a user's
browser session in context of an affected site.
The vulnerability is reported in versions prior to 1.1.12.
SOLUTION:
Update to version 1.1.12 or later.
PROVIDED AND/OR DISCOVERED BY:
Fukumori
ORIGINAL ADVISORY:
Seasar:
http://mayaa.seasar.org/news/vulnerability20070816.html
JVN:
http://jvn.jp/jp/JVN%2338199598/index.html

Moderator
CNET Staff
Samsung Staff
Dell Staff