PT-2006-6567 · Zend · Zend Framework
Publicado
2006-11-15
·
Atualizado
2018-10-17
·
CVE-2006-5900
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Zend Framework Preview version 0.2.0
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via arbitrary parameters in the incubator/tests/Zend/Http/ files/testRedirections.php sample code.
Recommendations
For Zend Framework Preview version 0.2.0, consider restricting access to the testRedirections.php sample code until a fix is available. As a temporary workaround, avoid using arbitrary parameters in the affected sample code to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Zend Framework