PT-2005-4810 · Ideal · Ideal Bb.Net

Publicado

2005-12-08

·

Atualizado

2017-07-20

·

CVE-2005-4078

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Ideal BB.NET versions 1.3 and earlier
Description The issue allows remote attackers to inject arbitrary web script or HTML via several parameters in different API endpoints, including the forumID, boardID, and topicRepeater1-p parameters in "topics.aspx", the boardID parameter in "categoryindex.aspx", the postID parameter in "posts.aspx", the catID parameter in "forums.aspx", and the memberID parameter in "member.aspx".
Recommendations For Ideal BB.NET versions 1.3 and earlier, as a temporary workaround, consider restricting access to the vulnerable parameters forumID, boardID, topicRepeater1-p, postID, catID, and memberID in their respective API endpoints until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4078

Produtos afetados

Ideal Bb.Net