Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Shen139

Pesquisador deBADROOT SECURITY GROUP
#51177de 53,633
4.3CVSS total
Vulnerabilidades · 1
PT-2005-3095
4.3
2005-07-06
Unknown · Autoindex Php Script · CVE-2005-2163
Name of the Vulnerable Software and Affected Versions: AutoIndex PHP Script version 1.5.2 Description: A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the `search` parameter in the "index.php" file. Recommendations: For AutoIndex PHP Script version 1.5.2, consider validating and sanitizing user input for the `search` parameter to prevent XSS attacks. As a temporary workaround, restrict access to the "index.php" file until a patch is available.