Lucene search

K
jvnJapan Vulnerability NotesJVN:25448394
HistoryJun 04, 2008 - 12:00 a.m.

JVN#25448394 Sleipnir and Grani vulnerable to arbitrary script execution when Bookmark search results are restored from history

2008-06-0400:00:00
Japan Vulnerability Notes
jvn.jp
19

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

65.5%

Sleipnir and Grani, web browsers from Fenrir & Co., have a bookmark search function. When a user runs the search function, the search result is displayed in the web browser. If a specially crafted string is used in a search, an arbitrary script may be executed on the user’s web browser when the search results are restored from history.

Impact

An arbitrary script may be executed in the user’s web browser.

Solution

Update the Software
Apply the latest updates provided by Fenrir & Co.

Products Affected

  • Sleipnir 2.7.1 Release2 and earlier
  • Portable Sleipnir 2.7.1 Release2 and earlier
  • Grani 3.1 and earlier

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.003

Percentile

65.5%

Related for JVN:25448394