PT-2005-4209 · Eyeos · Eyeos

Publicado

2005-11-01

·

Atualizado

2017-07-11

·

CVE-2005-3413

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions eyeOS version 0.8.4
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the motd parameter in the "desktop.php" file.
Recommendations For eyeOS version 0.8.4, avoid using the motd parameter in the desktop.php file until a fix is available. Consider restricting access to the desktop.php file to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3413

Produtos afetados

Eyeos