Vulnerabilidades en gres webNetwork
|
Clasificación de la vulnerabilidad
|
|
Propiedad |
Valor |
|
Nivel de Confianza |
Oficial |
|
Impacto |
Obtener acceso |
|
Dificultad |
Avanzado |
|
Requerimientos del atacante |
Acceso remoto sin cuenta a un servicio estandar |
Información sobre el sistema
|
|
Propiedad |
Valor |
|
Fabricante afectado |
Comercial Software |
|
Software afectado |
Stone-ware Webnetwork 6.1 |
Descripción
|
|
Se han descubierto múltiples vulnerabilidades de tipo cross-site scripting (XSS) en gres webNetwork, versiones anteriores a v6.1 SP1, que podrían permitir a atacantes remotos inyectar secuencias de comandos web o HTML mediante varios parámetros. |
Solución
|
|
Actualizar a webNetwork 6.1 Service Pack 1. |
Identificadores estándar
|
|
Propiedad |
Valor |
|
CVE |
CVE-2012-4352 |
|
BID |
|
Recursos adicionales
|
Stoneware Security Bulletin
http://stoneware-docs.s3.amazonaws.com/Bulletins/Security%20Bulletin%206_1_0.pdf |