PT-2014-01: Cross-Site Scripting in Nixu Namesurfer
Version: 7.2.2 and earlier
Severity level: Medium
Impact: Cross-Site Scripting
Access Vector: Remote
Base Score: 4.3
CVE: not assigned
Nixu Namesurfer implements a unified system for manageming DNS servers via web interface.
The specialists of the Positive Research center have detected a Cross-Site Scripting vulnerability in Nixu Namesurfer.
The vulnerability allows an attacker to inject a malicious code into a page generated by the web-based system. This code will be executed on the victim’s computer when he/she opens this page. At that, the malicious code will interact with the attacker’s web server.
How to fix
Update your sofware up to the latest version
16.01.2014 - Vendor gets vulnerability details
14.03.2014 - Vendor releases fixed version and details
27.03.2014 - Public disclosure
The vulnerability was detected by Alexey Osipov, Alexander Tlyapov, and Valentin Shilnenkov, Positive Research Center (Positive Technologies Company)
Reports on the vulnerabilities previously discovered by Positive Research: