PT-2005-2436 · Viart · Viart Shop Enterprise

Lostmon

·

Publicado

2005-05-03

·

Atualizado

2008-09-05

·

CVE-2005-1440

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: ViArt Shop Enterprise version 2.1.6
Description: The issue allows remote attackers to inject arbitrary web script or HTML via various parameters, including those in basket.php, forum.php, page.php, reviews.php, product details.php, products.php, and news view.php. This can be achieved by manipulating parameters such as nickname, email, topic, message, page, category id, item id, search string, rp, or page.
Recommendations: For ViArt Shop Enterprise version 2.1.6, consider disabling the vulnerable parameters to mitigate the risk of exploitation until a patch is available. Restrict access to the affected scripts, such as basket.php, forum.php, page.php, reviews.php, product details.php, products.php, and news view.php, to minimize the risk of exploitation. Avoid using the vulnerable parameters, such as nickname, email, topic, message, page, category id, item id, search string, rp, or page, in the affected API endpoints until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1440

Produtos afetados

Viart Shop Enterprise