PT-2006-6827 · B2Evolution · B2Evolution

Tarkus

·

Publicado

2006-12-01

·

Atualizado

2018-10-17

·

CVE-2006-6197

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions b2evolution versions 1.8.2 through 1.9 beta
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the app name parameter in files such as 404 not found.page.php, 410 stats gone.page.php, and referer spam.page.php in the inc/VIEW/errors/ directory, the baseurl parameter in 404 not found.page.php, and the ReqURI parameter in referer spam.page.php.
Recommendations For b2evolution versions 1.8.2 through 1.9 beta, consider disabling the app name, baseurl, and ReqURI parameters in the affected files until a patch is available. Restrict access to the inc/VIEW/errors/ directory to minimize the risk of exploitation. Avoid using the app name parameter in 404 not found.page.php, 410 stats gone.page.php, and referer spam.page.php, the baseurl parameter in 404 not found.page.php, and the ReqURI parameter in referer spam.page.php in the affected API endpoints until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6197

Produtos afetados

B2Evolution