PT-2008-2891 · Alkacon · Opencms

Nnposter

·

Publicado

2008-03-12

·

Atualizado

2022-05-01

·

CVE-2008-1300

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Alkacon OpenCms versions 7.0.3 through 7.0.4
Description A cross-site scripting (XSS) issue exists in the Logfile Viewer Settings function, allowing remote attackers to inject arbitrary web script or HTML via the filePath.0 parameter in a save action.
Recommendations For versions 7.0.3 and 7.0.4, avoid using the filePath.0 parameter in the save action of the Logfile Viewer Settings function until a fix is available. As a temporary workaround, consider restricting access to the Logfile Viewer Settings function to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1300
GHSA-W3V2-VFRJ-J9G8

Produtos afetados

Opencms