PT-2006-2046 · N8Cms · N8Cms

Liz0

·

Publicado

2006-03-06

·

Atualizado

2018-10-18

·

CVE-2006-1008

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions N8cms versions 1.1 through 1.2
Description The issue allows remote attackers to inject arbitrary web script or HTML, potentially resulting from SQL injection. This can be achieved via the dir and page id parameters to "index.php" and the userid parameter to "mailto.php".
Recommendations For versions 1.1 and 1.2, consider restricting access to the index.php and mailto.php files until a patch is available. As a temporary workaround, avoid using the dir, page id, and userid parameters in the affected API endpoints.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1008

Produtos afetados

N8Cms