PT-2006-5323 · Unknown · Membrepass

Darkfig

·

Publicado

2006-09-01

·

Atualizado

2018-10-17

·

CVE-2006-4528

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions membrepass version 1.5
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. Specifically, the "recherche" parameter in "recherchemembre.php" and the "email" parameter in "test.php" are vulnerable.
Recommendations For membrepass version 1.5, consider restricting access to the "recherchemembre.php" and "test.php" scripts until a fix is available, and avoid using the recherche and email parameters in these scripts to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4528

Produtos afetados

Membrepass