Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Vampire_Chiristof

#51047de 53,622
4.3CVSS total
Vulnerabilidades · 1
PT-2006-5041
4.3
2006-08-18
Vwar · Virtual War · CVE-2006-4224
**Name of the Vulnerable Software and Affected Versions** Virtual War (VWar) versions 1.5.0 and earlier **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the `year` parameter in the calendar.php file. **Recommendations** For versions 1.5.0 and earlier, consider restricting access to the calendar.php file until a fix is available, and avoid using the `year` parameter in this context to minimize the risk of exploitation.