Home Services Publications News About us Contact Recruitment Site map

June, 2008

May, 2008

April, 2008

March, 2008

February, 2008

January, 2008


News archives

News
January 14, 2008
Meridio Advisory released


An advisory relating to a cross site scripting vulnerability discovered by MWR InfoSecurity was released through CPNI today.

Meridio Document and Records Management has been identified as being vulnerable to an embedded Cross Site Scripting attack that could potentially allow remote attackers to inject JavaScript into the application. This would then be executed within the context of the browser of the application user.

The impact of this attack is only limited by the creativity of the attacker exploiting this vulnerability. The most dangerous form of XSS involves hostile code being permanently stored within the application. This means the embedded code would be executed by every user accessing the affected page and this is the case in this instance.

Meridio have addressed this vulnerability and implemented a fix in version 4.3 SR1 and higher.  The full advisory can be viewed here.

On Top
Penetration testing
Application Security Testing
Wireless Testing
Fasthold Vulnerability Assessment
Load Testing
Security Management Consultancy
Firewall Testing
Internal Penetration Testing
Physical Testing

 

home       services       news       about us       contact       recruitment       sitemap

MWR InfoSecurity St Clement House Alencon Link Basingstoke Hants RG21 7SB
Tel: 01256 300920   Fax: 01256 844083