PT-2007-1275 · Warforge · Warforge.News

Publicado

2007-02-12

·

Atualizado

2017-07-29

·

CVE-2006-6996

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions warforge.NEWS version 1.0
Description The issue allows remote attackers to inject arbitrary HTML and web script via specific parameters to certain PHP files. The vulnerable parameters include title and newspost in "newsadd.php", and name, title, and comment in "news.php".
Recommendations For warforge.NEWS version 1.0, consider restricting access to the "newsadd.php" and "newsphp" files until a fix is available, and avoid using the vulnerable parameters title, newspost, name, and comment in these files. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6996

Produtos afetados

Warforge.News