Overview
Pluck SiteLife software contains multiple XSS vulnerabilities.
Description
According to DemandMedia's website Pluck SiteLife software is an integrated community platform architected for brands. Pluck SiteLife software contains multiple cross site scripting (XSS) vulnerabilities. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Impact
An attacker with access to the Pluck SiteLife software can conduct a cross site scripting attack, which could be used to result in information leakage, privilege escalation, and/or denial of service. |
Solution
Apply an Update |
Restrict access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6 | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Temporal | 5 | E:F/RL:OF/RC:C |
Environmental | 3.8 | CDP:N/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Phil Purviance for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2012-0253 |
Date Public: | 2012-04-10 |
Date First Published: | 2012-04-10 |
Date Last Updated: | 2012-04-12 15:11 UTC |
Document Revision: | 21 |