PT-2007-7320 · Lineshout · Lineshout
Publicado
2007-12-20
·
Atualizado
2017-08-08
·
CVE-2007-6486
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
LineShout version 1.0
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The injection can occur via the
username (also referred to as nickname) or message parameter in the shout.php file, also known as the shoutbox.Recommendations
For LineShout version 1.0, consider restricting the input for the
username and message parameters to prevent the injection of malicious scripts until a fix is available. As a temporary workaround, disabling the shoutbox functionality in shout.php could minimize the risk of exploitation.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Lineshout