mvnForum activatemember Multiple Parameter XSS

This script is Copyright (C) 2006-2013 Tenable Network Security, Inc.


Synopsis :

The remote web server contains a Java application that is affected by
several cross-site scripting issues.

Description :

The remote host is running mvnForum, an open source, forum application
based on Java J2EE.

The version of mvnForum installed on the remote host fails to sanitize
user-supplied input to the 'activatecode' and 'member' parameters of
the 'activatemember' script before using it to generate dynamic web
content. Successful exploitation of this issue may lead to the
execution of arbitrary HTML and script code in a user's browser within
the context of the affected application.

See also :

http://pridels0.blogspot.com/2006/06/mvnforum-xss-vuln.html

Solution :

Unknown at this time.

Risk factor :

Low / CVSS Base Score : 2.6
(CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 2.5
(CVSS2#E:F/RL:U/RC:ND)
Public Exploit Available : true

Family: CGI abuses : XSS

Nessus Plugin ID: 21757 ()

Bugtraq ID: 18663

CVE ID: CVE-2006-3245