PT-2006-2414 · Sweetsuite.Net · Sweetsuite.Net Content Management System

Publicado

2006-03-28

·

Atualizado

2017-07-20

·

CVE-2006-1405

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SweetSuite.NET Content Management System (ssCMS) versions 2.1.0 and earlier
Description The issue is related to a cross-site scripting (XSS) vulnerability. It affects the search.aspx page in the SweetSuite.NET Content Management System (ssCMS), allowing remote attackers to inject arbitrary web script or HTML via the keywords parameter.
Recommendations For versions 2.1.0 and earlier, update to a version later than 2.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the search.aspx page or avoiding the use of the keywords parameter until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1405

Produtos afetados

Sweetsuite.Net Content Management System