PT-2005-4610 · Searchfeed · Searchfeed Search Engine

Publicado

2005-11-29

·

Atualizado

2017-07-20

·

CVE-2005-3866

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SearchFeed Search Engine versions 1.3.2 and earlier
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary HTML and web script. The REQ parameter, used during search operations, is potentially involved in the exploitation of this issue.
Recommendations For SearchFeed Search Engine versions 1.3.2 and earlier, as a temporary workaround, consider restricting the use of the REQ parameter in search operations until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3866

Produtos afetados

Searchfeed Search Engine