PT-2005-3454 · Gbx · Gravity Board X

Retrogod

·

Publicado

2005-08-16

·

Atualizado

2016-10-18

·

CVE-2005-2563

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Gravity Board X (GBX) version 1.1
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. Specifically, the board id parameter to deletethread.php and the template are vulnerable.
Recommendations For Gravity Board X (GBX) version 1.1, avoid using the board id parameter in the deletethread.php endpoint and restrict access to the template until a fix is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2563

Produtos afetados

Gravity Board X