PT-2002-2717 · Postnuke · Postnuke

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-1996

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PostNuke versions 0.71 and earlier
Description A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the name parameter in "modules.php" and the catid parameter in "index.php".
Recommendations For PostNuke versions 0.71 and earlier, avoid using the name parameter in "modules.php" and the catid parameter in "index.php" until a fix is applied. As a temporary workaround, consider restricting access to "modules.php" and "index.php" to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1996

Produtos afetados

Postnuke