Cross-site scripting (XSS) vulnerability in Mayaa before 1.1.12 allows remote attackers to inject arbitrary web script or HTML in certain circumstances involving (1) lack of charset specification within a META element or (2) a META element that specifies an unrecognized charset, which trigger automatic character set recognition by the web browser, as demonstrated by improper handling of UTF-7 data.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/25443 | vdb entry |
http://secunia.com/advisories/26597 | third party advisory patch vendor advisory |
http://jvn.jp/jp/JVN%2338199598/index.html | third party advisory |
http://mayaa.seasar.org/news/vulnerability20070816.html | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36269 | vdb entry |
http://osvdb.org/36655 | vdb entry |