PT-2004-3560 · Endonesia · Endonesia
Publicado
2004-12-31
·
Atualizado
2017-07-29
·
CVE-2004-2670
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
eNdonesia version 8.3
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities in the mod.php file of eNdonesia. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. This can be achieved through two main vectors: (1) the
mod parameter in a 'viewcat' operation or (2) the query parameter in a 'search' operation within the publisher module.Recommendations
For eNdonesia version 8.3, consider disabling the mod.php file or restricting access to the 'viewcat' and 'search' operations in the publisher module until a patch is available. Avoid using the
mod and query parameters in these operations to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Endonesia