PT-2005-4166 · Sparkleblog · Sparkleblog
Sikik
·
Publicado
2005-10-29
·
Atualizado
2016-10-18
·
CVE-2005-3367
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SparkleBlog version 2.1
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the
name field in the journal.php file.Recommendations
For SparkleBlog version 2.1, consider restricting input to the
name field in the journal.php file to prevent arbitrary web script or HTML injection until a patch is available.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sparkleblog