PT-2007-1855 · Postnuke · Postnuke
Publicado
2007-01-19
·
Atualizado
2008-11-13
·
CVE-2007-0384
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
PostNuke version 0.764
Description:
A cross-site scripting (XSS) issue exists in the preview functionality of the reviews section, allowing remote attackers to inject arbitrary web script or HTML. This is achieved through unspecified vectors.
Recommendations:
For PostNuke version 0.764, consider disabling the preview functionality in the reviews section as a temporary workaround until a patch is available. Restrict access to the reviews section to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Postnuke