PT-2005-5021 · Binary Board System · Binary Board System

Publicado

2005-12-17

·

Atualizado

2008-09-20

·

CVE-2005-4333

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Binary Board System (BBS) versions 0.2.5 and earlier
Description The issue allows remote attackers to inject arbitrary web script or HTML via specific parameters to various scripts. The vulnerable parameters include inreplyto, article, and board to reply.pl, branch, board, and parameters to stats.pl, and board parameter to toc.pl.
Recommendations For Binary Board System (BBS) versions 0.2.5 and earlier, consider restricting access to the reply.pl, stats.pl, and toc.pl scripts until a fix is available. As a temporary workaround, avoid using the inreplyto, article, board, branch, and other vulnerable parameters in the affected scripts.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4333

Produtos afetados

Binary Board System