PT-2006-7459 · Outfront · Outfront Spooky Login

Publicado

2006-12-31

·

Atualizado

2018-10-17

·

CVE-2006-6862

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Outfront Spooky Login version 2.7
Description: The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to API endpoints such as "login/login.asp" or "login/register.asp".
Recommendations: For Outfront Spooky Login version 2.7, as a temporary workaround, consider restricting access to the "login/login.asp" and "login/register.asp" API endpoints until a patch is available. Avoid using unspecified parameters in these endpoints to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6862

Produtos afetados

Outfront Spooky Login