PT-2006-2358 · Musicbox · Musicbox

Publicado

2006-03-22

·

Atualizado

2018-10-18

·

CVE-2006-1349

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Musicbox version 2.3 Beta 2
Description The issue allows remote attackers to inject arbitrary web script or HTML via specific parameters in certain PHP files. This can be achieved by manipulating the id, type, and show parameters in a top action in index.php, or the message1 parameter in cart.php.
Recommendations For Musicbox version 2.3 Beta 2, as a temporary workaround, consider restricting access to the index.php and cart.php files until a patch is available. Avoid using the id, type, show, and message1 parameters in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1349

Produtos afetados

Musicbox