PT-2006-3047 · Vbulletin+1 · Vbulletin+1

Mustafa Can Bjorn Ipekci

+1

·

Publicado

2006-04-27

·

Atualizado

2018-10-18

·

CVE-2006-2066

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MKPortal versions 1.1 Rc1 and earlier vBulletin versions 3.5.4 and earlier
Description The issue allows remote attackers to inject arbitrary web script or HTML via the u1, m1, m2, m3, m4 parameters in the pm popup.php file.
Recommendations For MKPortal versions 1.1 Rc1 and earlier, avoid using the parameters u1, m1, m2, m3, m4 in the pm popup.php file until a fix is available. For vBulletin versions 3.5.4 and earlier, restrict access to the pm popup.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-2066

Produtos afetados

Mkportal
Vbulletin