PT-2006-1182 · Sblog · Sblog

Publicado

2006-01-06

·

Atualizado

2017-07-20

·

CVE-2006-0101

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: sBLOG versions 0.7.1 Beta 20051202 and earlier
Description: The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the p and keyword parameters in the "index.php" and "search.php" API endpoints.
Recommendations: For sBLOG versions 0.7.1 Beta 20051202 and earlier, consider restricting access to the p and keyword parameters in the "index.php" and "search.php" endpoints until a fix is available. Avoid using these parameters in the affected API endpoints to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-0101

Produtos afetados

Sblog