PT-2005-4589 · Kplaylist · Kplaylist

Publicado

2005-11-26

·

Atualizado

2011-03-08

·

CVE-2005-3841

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions kPlaylist versions 1.6 (build 400) and possibly other versions
Description The issue allows remote attackers to inject arbitrary web script or HTML via the searchfor search parameter. This can lead to cross-site scripting (XSS) attacks.
Recommendations For version 1.6 (build 400), avoid using the searchfor parameter in the search functionality until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3841

Produtos afetados

Kplaylist