PT-2005-4969 · Zaygo · Zaygo Hostingcart

Publicado

2005-12-16

·

Atualizado

2011-03-08

·

CVE-2005-4281

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Zaygo HostingCart versions 2.0 and earlier
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via certain search module parameters, possibly the root parameter to "zaygo.cgi".
Recommendations For Zaygo HostingCart versions 2.0 and earlier, consider disabling the search module or restricting access to the root parameter in "zaygo.cgi" until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4281

Produtos afetados

Zaygo Hostingcart