Ichitaro 2005 through 2007, and possibly related products, allows remote attackers to have an unknown impact via unspecified vectors in a document distributed through e-mail or a web site, possibly due to a buffer overflow or cross-site scripting (XSS).
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2007/1287 | vdb entry vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/33507 | vdb entry |
http://osvdb.org/34759 | vdb entry |
http://secunia.com/advisories/24780 | third party advisory vendor advisory |
http://vil.mcafeesecurity.com/vil/content/v_141950.htm | |
http://www.securitytracker.com/id?1017887 | vdb entry |
http://www.justsystem.co.jp/info/pd7002.html | |
http://www.securityfocus.com/bid/23386 | vdb entry |