PT-2008-3990 · Phoenix View · Phoenix View Cms

Tw8

·

Publicado

2008-06-03

·

Atualizado

2017-09-29

·

CVE-2008-2533

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Phoenix View CMS versions Pre Alpha2 and earlier
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the ltarget parameter to "admin/admin frame.php" and the conf parameter to several files in "admin/module/", including "gbuch.admin.php", "links.admin.php", "menue.admin.php", "news.admin.php", and "todo.admin.php".
Recommendations For Phoenix View CMS versions Pre Alpha2 and earlier, consider disabling access to the vulnerable parameters ltarget and conf in the affected files until a patch is available. Restrict access to the admin/module/ directory to minimize the risk of exploitation. Avoid using the ltarget parameter in "admin/admin frame.php" and the conf parameter in the specified admin files until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2533

Produtos afetados

Phoenix View Cms