PT-2007-4273 · Centrinity · Centrinity Server/Internet Services+1

Publicado

2007-06-01

·

Atualizado

2017-07-29

·

CVE-2007-2976

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Centrinity FirstClass versions 8.3 and earlier Centrinity Server and Internet Services versions 8.0 and earlier
Description The issue arises from improper handling of a URL with a null ("%00") character, allowing remote attackers to conduct cross-site scripting (XSS) attacks.
Recommendations For Centrinity FirstClass versions 8.3 and earlier, update to a version later than 8.3 to resolve the issue. For Centrinity Server and Internet Services versions 8.0 and earlier, update to a version later than 8.0 to resolve the issue. As a temporary workaround, consider restricting access to URLs that may contain null characters until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2976

Produtos afetados

Centrinity Firstclass
Centrinity Server/Internet Services