PT-2005-1705 · Mercury · Mercuryboard

Publicado

2005-03-07

·

Atualizado

2008-09-05

·

CVE-2005-0662

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MercuryBoard version 1.1.2
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the Avatar field in index.php. This could potentially lead to unauthorized actions on the affected system.
Recommendations For MercuryBoard version 1.1.2, consider validating and sanitizing user input for the Avatar field to prevent the injection of malicious scripts. As a temporary workaround, restrict access to the Avatar field until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0662

Produtos afetados

Mercuryboard