Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Grossman

#51730de 53,633
4.3CVSS total
Vulnerabilidades · 1
PT-2008-2068
4.3
2008-01-23
Pd9 · Megabbs · CVE-2008-0436
**Name of the Vulnerable Software and Affected Versions** PD9 Software MegaBBS version 1.5.14b **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the `target` parameter in the "profile-upload/upload.asp" endpoint. **Recommendations** For version 1.5.14b, consider restricting access to the "profile-upload/upload.asp" endpoint until a fix is available, and avoid using the `target` parameter in this endpoint to minimize the risk of exploitation.