PT-2005-4166 · Sparkleblog · Sparkleblog

Sikik

·

Publicado

2005-10-29

·

Atualizado

2016-10-18

·

CVE-2005-3367

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SparkleBlog version 2.1
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the name field in the journal.php file.
Recommendations For SparkleBlog version 2.1, consider restricting input to the name field in the journal.php file to prevent arbitrary web script or HTML injection until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3367

Produtos afetados

Sparkleblog