CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
Percentile
68.2%
a-News, a web log system from Appleple, contains a cross-site scripting vulnerability.
Note that future releases and maintenance of a-News ended on May 14, 2009. The developer recommends users who wish to continue using a web log system to use a-blog.
An arbitrary script may be executed on the user’s web browser.
Do not use a-News
As patches will not be provided, the developer recommends to discontinue the use of a-News and switch to a-blog.