This application requires Javascript for optimal performance.

HTTP.UserAgent.HTML.Injection

Alias(es)

ReloadCMS.UserAgent.HTML.Injection

Release Date

Feb 02, 2007

Severity

low

Impact

HTML or php code injection.

Description

A vulnerability has been identified in ReloadCMS, which may be exploited by attackers to execute arbitrary scripting code. This flaw is due to an input validation error in the administrative interface that does not validate the "User-Agent" header before it is displayed by the statistics module, which could be exploited by attackers to cause arbitrary scripting code to be executed by the administrator's browser in the security context of an affected Web site.

Affected Products

ReloadCMS version 1.2.5 and prior

Recommended Actions

Currently we are not aware of any vendor-supplied patches for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-1645

Reference/s

http://www.securityfocus.com/bid/17353 (BugTraq)

Reference: VID-14006