PT-2002-2671 · Phprank · Phprank
Publicado
2002-12-31
·
Atualizado
2008-09-05
·
CVE-2002-1950
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
phpRank version 1.8
Description
The issue is related to a cross-site scripting (XSS) vulnerability. This allows remote attackers to inject arbitrary web script or HTML. Specifically, the vulnerability can be exploited through the
email parameter of "add.php" or the banurl parameter, which is the banner URL in the main list.Recommendations
For phpRank version 1.8, as a temporary workaround, consider validating and sanitizing user input for the
email parameter in "add.php" and the banurl parameter to prevent malicious script injections. Restrict access to "add.php" and limit the ability to set the banner URL to trusted users until a fix is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phprank