PT-2005-3762 · Cjlinkout · Cjlinkout

Psymera

·

Publicado

2005-09-14

·

Atualizado

2016-10-18

·

CVE-2005-2900

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions CjLinkOut version 1.0
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the 123 parameter in the top.php file. This could potentially lead to unauthorized actions on the affected system.
Recommendations For CjLinkOut version 1.0, consider restricting access to the top.php file or avoiding the use of the 123 parameter until a fix is available. As a temporary workaround, disabling the execution of scripts from this parameter may help mitigate the risk.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2900

Produtos afetados

Cjlinkout