Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Unsticky

#52160de 53,635
4.3CVSS total
Vulnerabilidades · 1
PT-2007-1659
4.3
2007-01-11
B2Evolution · B2Evolution · CVE-2007-0175
**Name of the Vulnerable Software and Affected Versions** b2evolution version 1.8.6 **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via scriptable attributes in the `redirect to` parameter in the htsrv/login.php file. **Recommendations** For version 1.8.6, consider restricting access to the htsrv/login.php file until a patch is available, and avoid using scriptable attributes in the `redirect to` parameter to minimize the risk of exploitation.