PT-2005-1414 · Emotion · Emotion Mediapartner Web Server
Paul J Docherty
·
Publicado
2005-02-10
·
Atualizado
2017-07-11
·
CVE-2005-0336
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
EMotion MediaPartner Web Server version 5.0
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary HTML or web script. This can be demonstrated using a URL containing .. sequences and HTML, resulting in a directory browsing page that does not properly filter the HTML.
Recommendations
For EMotion MediaPartner Web Server version 5.0, consider implementing proper HTML filtering for the directory browsing page to prevent arbitrary HTML or web script injection. As a temporary workaround, restrict access to the directory browsing functionality until a proper fix is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Emotion Mediapartner Web Server