PT-2004-2861 · Nqt · Network Query Tool

Publicado

2004-04-23

·

Atualizado

2017-07-11

·

CVE-2004-1964

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Network Query Tool (NQT) version 1.6
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the portNum parameter in the nqt.php file. This could potentially lead to unauthorized actions on the affected system.
Recommendations For Network Query Tool (NQT) version 1.6, avoid using the portNum parameter in the nqt.php file until a fix is available. As a temporary workaround, consider restricting access to the nqt.php file to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1964

Produtos afetados

Network Query Tool