PT-2007-1193 · Dt · Dm Guestbook

Jesper Jurcenoks

·

Publicado

2007-01-16

·

Atualizado

2018-10-17

·

CVE-2006-6487

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: DT Guestbook version 1.0f
Description: A cross-site scripting issue exists due to the lack of proper input validation in the index.php file of DT Guestbook. When the register globals setting is enabled, remote attackers can inject arbitrary web script or HTML via the error[] parameter.
Recommendations: For DT Guestbook version 1.0f, consider disabling the register globals setting to prevent exploitation. Additionally, restrict access to the index.php file until a proper fix is applied, and avoid using the error[] parameter in sensitive operations.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6487

Produtos afetados

Dm Guestbook