PT-2006-2756 · Jbook · Jbook

Publicado

2006-04-13

·

Atualizado

2018-10-18

·

CVE-2006-1765

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JBook version 1.3
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the page parameter in the "index.php" file.
Recommendations For JBook version 1.3, consider validating and sanitizing user input for the page parameter to prevent XSS attacks. As a temporary workaround, restrict access to the "index.php" file until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1765

Produtos afetados

Jbook