PT-2005-5138 · Unknown · Cleanhtml.Pl
Publicado
2005-12-21
·
Atualizado
2008-09-05
·
CVE-2005-4455
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
cleanhtml.pl version 1.129
Description
The issue allows remote attackers to inject scripting languages via the XSL namespace in XML. This can be achieved through vectors such as customview.cgi.
Recommendations
For cleanhtml.pl version 1.129, consider updating to a version released after Dec 13 2005 to resolve the issue. As a temporary workaround, restrict access to customview.cgi to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cleanhtml.Pl