PT-2006-5776 · Vmware · Vcap

Publicado

2006-09-27

·

Atualizado

2011-03-08

·

CVE-2006-5035

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions vCAP version 1.7.0
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the statusmsg parameter in RegisterPage.cgi or a URI corresponding to a nonexistent file.
Recommendations For version 1.7.0, consider restricting access to the RegisterPage.cgi endpoint and avoid using the statusmsg parameter until a fix is available. Additionally, restrict access to URIs corresponding to nonexistent files to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-5035

Produtos afetados

Vcap