PT-2007-7323 · Falcon · Falcon Series One Cms

Mhz91

·

Publicado

2007-12-20

·

Atualizado

2017-09-29

·

CVE-2007-6489

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Falcon Series One CMS version 1.4.3
Description The issue allows remote attackers to inject arbitrary web script or HTML via the gb mail, gb name, and gb text parameters in a guestbook action to "index.php", and unspecified other vectors. This can lead to cross-site scripting (XSS) attacks.
Recommendations For Falcon Series One CMS version 1.4.3, as a temporary workaround, consider restricting access to the guestbook action in "index.php" and avoid using the gb mail, gb name, and gb text parameters until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-6489

Produtos afetados

Falcon Series One Cms