PT-2006-3671 · Osic · Open Searchable Image Catalogue

Nenad Jovanovic

·

Publicado

2006-06-01

·

Atualizado

2018-10-18

·

CVE-2006-2751

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Open Searchable Image Catalogue (OSIC) versions 0.7.0.1 and earlier
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web scripts or HTML via the item list parameter in the "search.php" endpoint. This could potentially lead to unauthorized actions on the affected system.
Recommendations For OSIC versions 0.7.0.1 and earlier, as a temporary workaround, consider restricting access to the "search.php" endpoint or sanitizing the item list parameter to prevent malicious input until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2751

Produtos afetados

Open Searchable Image Catalogue