PT-2005-1674 · 427Bb · 427Bb

Th3_R@V3N

·

Publicado

2005-03-01

·

Atualizado

2017-07-11

·

CVE-2005-0629

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions 427BB version 2.2
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via the user or Avatar parameters in the profile.php file.
Recommendations For version 2.2, update to a version that includes a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting input for the user and Avatar parameters to minimize the risk of XSS attacks.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0629

Produtos afetados

427Bb