PT-2003-2451 · Adelix · Adelix Censornet
Richard Maudsley
·
Publicado
2003-12-31
·
Atualizado
2017-07-29
·
CVE-2003-1506
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Adelix CensorNet versions 3.0 through 3.2
Description
A cross-site scripting (XSS) issue allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the
DENIEDURL parameter. This enables attackers to perform actions on behalf of other users.Recommendations
For Adelix CensorNet versions 3.0 through 3.2, avoid using the
DENIEDURL parameter until a fix is available. As a temporary workaround, consider restricting access to the dansguardian.pl script to minimize the risk of exploitation.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Adelix Censornet