[原文]Multiple cross-site scripting (XSS) vulnerabilities in Pre News Manager 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e) printable_view.php, (f) tella_friend.php, and (g) send_comments.php.
Pre News Manager contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the \'id\' variable upon submission to the index.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user\'s browser within the trust relationship between the browser and the server, leading to a loss of integrity.
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
Luny is credited with discovering this vulnerability.
Pre Projects Pre News Manager 1.0
Pre News Manager is prone to multiple cross-site scripting vulnerabilities because it fails to sanitize input before displaying it to users.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Attackers can use a browser to exploit this issue.