Release date:
Updated on:
Affected Systems:
Iscripts iScripts EasyCreate 2.x
Description:
--------------------------------------------------------------------------------
IScripts EasyCreate is an online website building tool that can be used on servers to provide website building services for clients. It is completely customizable.
IScripts EasyCreate v2.0 CMS has multiple Web security vulnerabilities, which are passed to editprofile through the "vuser_name" parameter. php ("act" is set to "post") is used when input is not properly filtered. Attackers can insert arbitrary HTML and script code, and then view malicious data by victims, execute the code in a browser session.
<* Source: Ibrahim El-Sayed
Link: http://www.vulnerability-lab.com/get_content.php? Id = 588
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Iscripts
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.iscripts.com/easycreate