
Cobalt RAQ 4 のクロスサイトスクリプティングの脆弱性により、リモートの攻撃者が (1) service.cgi または (2) alert.cgi への URL 内の JavaScript を介して、他の Cobalt ユーザーとして任意のスクリプトを実行できる可能性があります。
Packetstorm 公開: https://packetstormsecurity.com/files/25837/Colbalt-RAQ-v4.txt.html
SecurityFocus 公開: https://www.securityfocus.com/bid/4211
Alex Hernandez 別名 (@_alt3kx_)
ベンダーに通知されました。
公開リスト^s Security cobalt:
[email protected] &
[email protected]
http://www.cobalt.com
システムから cgi^s ファイルを削除するか、その実行を無効にしてください。