PT-2007-1301 · Fx-App · Fx-App
Luny
·
Publicado
2007-02-15
·
Atualizado
2018-10-16
·
CVE-2006-7022
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
fx-APP version 0.0.8.1
Description
The issue allows remote attackers to misrepresent the contents of a web page by providing an arbitrary URL in the
url parameter to a "showhtml" action for "index.php", causing the URL to be displayed within an iframe.Recommendations
For fx-APP version 0.0.8.1, consider restricting access to the "showhtml" action for "index.php" to minimize the risk of exploitation, and avoid using the
url parameter in the affected API endpoint until the issue is resolved.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Fx-App