Summary
The remote host is missing an update to b2evolution announced via advisory DSA 1568-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201568-1
Insight
unsticky discovered that b2evolution, a blog engine, performs insufficient input sanitising, allowing for cross site scripting.
For the stable distribution (etch), this problem has been fixed in version 0.9.2-3+etch1.
For the unstable distribution (sid), this problem has been fixed in version 0.9.2-4.
We recommend that you upgrade your b2evolution (0.9.2-3+etch1) package.
Severity
Classification
-
CVE CVE-2007-0175 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities