PT-2006-5243 · Php · Php Address Book
Publicado
2006-08-29
·
Atualizado
2011-03-08
·
CVE-2006-4442
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHP iAddressBook versions prior to 0.95
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the
cat name parameter, related to adding a category. This is associated with the categories field.Recommendations
For versions prior to 0.95, update to version 0.95 or later to resolve the issue. As a temporary workaround, consider restricting access to the categories field or avoiding the use of the
cat name parameter until the issue is resolved.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Php Address Book