|
Amiro.CMS contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'status_message' parameter upon submission to the '/news', '/comment', '/forum', '/blog', '/tags', '/_admin/forum.php', '/_admin/discussion.php', '/_admin/guestbook.php', '/_admin/blog.php', '/_admin/news.php', '/_admin/google_sitemap.php', '/_admin/sitemap_history.php', '/_admin/locales.php' and '/_admin/plugins_wizard.php' scripts. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|