PT-2006-2832 · Bmachine · Boastmachine

Publicado

2006-04-19

·

Atualizado

2018-10-18

·

CVE-2006-1841

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions boastMachine (bMachine) versions 2.7 through 2.9b
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the key parameter in the search field, specifically in the search.php file.
Recommendations For boastMachine (bMachine) versions 2.7 through 2.9b, consider updating to a version after 2.9b to resolve the issue. As a temporary workaround, restrict access to the search field in search.php to minimize the risk of exploitation. Avoid using the key parameter in the search field until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1841

Produtos afetados

Boastmachine