PT-2005-1414 · Emotion · Emotion Mediapartner Web Server

Paul J Docherty

·

Publicado

2005-02-10

·

Atualizado

2017-07-11

·

CVE-2005-0336

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions EMotion MediaPartner Web Server version 5.0
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary HTML or web script. This can be demonstrated using a URL containing .. sequences and HTML, resulting in a directory browsing page that does not properly filter the HTML.
Recommendations For EMotion MediaPartner Web Server version 5.0, consider implementing proper HTML filtering for the directory browsing page to prevent arbitrary HTML or web script injection. As a temporary workaround, restrict access to the directory browsing functionality until a proper fix is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0336

Produtos afetados

Emotion Mediapartner Web Server