PT-2006-4078 · Mobescripts · Mobescripts Mobile Space Community

Luny

·

Publicado

2006-06-23

·

Atualizado

2017-07-20

·

CVE-2006-3183

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MobeScripts Mobile Space Community versions 2.0 and earlier
Description The issue allows remote attackers to inject arbitrary web script or HTML via the browse parameter, which is not filtered in the resulting error message, and multiple unspecified input fields, including those involved when updating a profile, posting comments or entries in a blog, uploading files, picture captions, and sending a private message (PM).
Recommendations For MobeScripts Mobile Space Community versions 2.0 and earlier, as a temporary workaround, consider filtering the browse parameter and restricting input in fields related to profile updates, blog comments, file uploads, picture captions, and private messages until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3183

Produtos afetados

Mobescripts Mobile Space Community