PT-2008-3760 · Mjguest · Mjguest

Dr.Crash

+1

·

Publicado

2008-05-16

·

Atualizado

2018-10-11

·

CVE-2008-2268

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Mjguest version 6.7 GT Rev.01
Description: The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. This is achieved via a URL in the goto parameter in a redirect action to "mjguest.php". The attack is user-assisted, meaning there is a delay and a notification before the redirection occurs.
Recommendations: For Mjguest version 6.7 GT Rev.01, consider restricting access to the "interface/redirect.htm.php" file or avoiding the use of the goto parameter in redirect actions to "mjguest.php" until a fix is available. As a temporary workaround, consider implementing additional validation for the goto parameter to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2008-2268

Produtos afetados

Mjguest