Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Charles H

Pesquisador deInfoGuard Group
#52355de 53,635
4CVSS total
Vulnerabilidades · 1
PT-2006-4038
4.0
2006-06-22
Maximus · Iparent · CVE-2006-3143
**Name of the Vulnerable Software and Affected Versions** Maximus SchoolMAX versions 4.0.1 and earlier iCue versions prior to 4.0.1 iParent versions prior to 4.0.1 **Description** The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability allows remote attackers to inject arbitrary web script or HTML via the `error msg` parameter in the icue login.asp file. **Recommendations** For Maximus SchoolMAX version 4.0.1 and earlier, update to a version later than 4.0.1. For iCue versions prior to 4.0.1, update to a version later than 4.0.1. For iParent versions prior to 4.0.1, update to a version later than 4.0.1. As a temporary workaround, consider restricting access to the icue login.asp file until a patch is available. Avoid using the `error msg` parameter in the affected icue login.asp file until the issue is resolved.