Description
Cross-site scripting vulnerability in namazu.cgi for Namazu 2.0.7 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the lang parameter.
Product(s):
- Namazu
- Namazu 0.1.0
- Namazu 0.1.1
- Namazu 0.1.2
- Namazu 0.1.3
- Namazu 0.1.4
- Namazu 0.2.0
- Namazu 0.2.1
- Namazu 0.2.2
- Namazu 0.3.0
- Namazu 0.3.1
- Namazu 0.3.2
- Namazu 0.3.3
- Namazu 1.0.0
- Namazu 1.0.1
- Namazu 1.0.2
- Namazu 1.0.3
- Namazu 1.0.4
- Namazu 1.0.4a
- Namazu 1.0.4b
- Namazu 1.1.0
- Namazu 1.1.0a
- Namazu 1.1.1.1
- Namazu 1.1.1.2
- Namazu 1.1.1.3
- Namazu 1.1.1.4
- Namazu 1.1.1.5
- Namazu 1.1.1
- Namazu 1.1.2.1
- Namazu 1.1.2.2
- Namazu 1.1.2.3
- Namazu 1.1.2.4
- Namazu 1.1.2.5
- Namazu 1.1.2
- Namazu 1.2.0.1
- Namazu 1.2.0.2
- Namazu 1.2.0.3
- Namazu 1.2.0.4
- Namazu 1.2.0.5 Beta 2
- Namazu 1.2.0
- Namazu 1.2.1.0 Beta 10
- Namazu 1.2.1.0 Beta 11
- Namazu 1.2.1.0 Beta 12
- Namazu 1.2.1.0 Beta 13
- Namazu 1.2.1.0 Beta 5
- Namazu 1.2.1.0 Beta 6
- Namazu 1.2.1.0 Beta 7
- Namazu 1.2.1.0 Beta 8
- Namazu 1.2.1.0 Beta 9
- Namazu 1.3.0.0
- Namazu 1.3.0.0 Beta 10
- Namazu 1.3.0.0 Beta 11
- Namazu 1.3.0.0 Beta 12
- Namazu 1.3.0.0 Beta 13
- Namazu 1.3.0.0 Beta 1
- Namazu 1.3.0.0 Beta 2
- Namazu 1.3.0.0 Beta 3
- Namazu 1.3.0.0 Beta 4
- Namazu 1.3.0.0 Beta 5
- Namazu 1.3.0.0 Beta 6
- Namazu 1.3.0.0 Beta 7
- Namazu 1.3.0.0 Beta 8
- Namazu 1.3.0.0 Beta 9
- Namazu 1.3.0.1
- Namazu 1.3.0.1 Beta 1
- Namazu 1.3.0.2
- Namazu 1.3.1.0 Alpha 10
- Namazu 1.3.1.0 Alpha 11
- Namazu 1.3.1.0 Alpha 1
- Namazu 1.3.1.0 Alpha 2
- Namazu 1.3.1.0 Alpha 3
- Namazu 1.3.1.0 Alpha 4
- Namazu 1.3.1.0 Alpha 5
- Namazu 1.3.1.0 Alpha 6
- Namazu 1.3.1.0 Alpha 7
- Namazu 1.3.1.0 Alpha 8
- Namazu 1.3.1.0 Alpha 9
- Namazu 1.4.0.0 Alpha 1
- Namazu 1.4.0.0 Alpha 2
- Namazu 1.4.0.0 Alpha 3
- Namazu 1.4.0.0 Alpha 4
- Namazu 1.4.0.0 Alpha 5
- Namazu 1.4.0.0 Alpha 6
- Namazu 1.4.0.0 Alpha 7
- Namazu 1.4.0.0 Beta 1
- Namazu 1.4.0.0 Beta 2
- Namazu 1.4.0.0 Beta 3
- Namazu 1.4.0.0 Beta 4
- Namazu 1.4.0.0 Beta 5
- Namazu 1.4.0.0 Beta 6
- Namazu 1.4.0.0 Beta 7
- Namazu 1.4.0.0 Beta 8
- Namazu 2.0.1
- Namazu 2.0.2
- Namazu 2.0.3
- Namazu 2.0.4
- Namazu 2.0.5
- Namazu 2.0.6
- Namazu 2.0.6 Pre1
- Namazu 2.0.6 Pre2
- +13 additional
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2001-1350, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2001-1350 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.