PT-2006-5707 · Maxdev · Maxdev Md-Pro

CVE-2006-4964

·

Publicado

2006-09-23

·

Atualizado

2024-02-14

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MAXdev MDPro versions prior to 1.0.76 (updated before 20060918)
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML. This is achieved through vectors that bypass the XSS protection mechanisms of the pnVarCleanFromInput function and unspecified vectors related to the AntiCracker.
Recommendations For MAXdev MDPro versions prior to 1.0.76, update to a version released after 20060918 to resolve the issue. As a temporary workaround, consider restricting input to prevent bypassing the XSS protection mechanisms until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4964

Produtos afetados

Maxdev Md-Pro