PT-2004-3057 · Tutos · Tutos
Joxean Koret
·
Publicado
2004-12-31
·
Atualizado
2017-07-11
·
CVE-2004-2162
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
TUTOS version 1.1
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The injection can occur via two main avenues: the search field of the Address Module or the
t parameter to "app new.php".Recommendations
For TUTOS version 1.1, consider disabling the search field in the Address Module and restricting access to the "app new.php" endpoint to minimize the risk of exploitation. Avoid using the
t parameter in the "app new.php" endpoint until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tutos