PT-2005-2834 · Lpanel · Lpanel
Publicado
2005-06-06
·
Atualizado
2008-09-05
·
CVE-2005-1877
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Lpanel versions 1.59 and earlier
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML and obtain sensitive information via the
pid parameter in the "view ticket.php" file.Recommendations
For Lpanel versions 1.59 and earlier, avoid using the
pid parameter in the view ticket.php file until a fix is available. As a temporary workaround, consider restricting access to the view ticket.php file to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Lpanel