Synopsis
The remote web server is affected by a cross-site scripting vulnerability.
Description
Siteframe 2.2.4 has a cross-site scripting bug. An attacker may use it to perform a cross-site scripting attack on this host.
In addition to this, another flaw in this package may allow an attacker to obtain the physical path to the remote web root.
Solution
Upgrade to a newer version.
Plugin Details
File Name: siteframe_xss.nasl
Configuration: Enable paranoid mode
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: www/PHP, Settings/ParanoidReport
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Reference Information
BID: 7140, 7143
CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990