PT-2008-4421 · Benja · Benja Cms

Publicado

2008-07-02

·

Atualizado

2018-10-11

·

CVE-2008-2987

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Benja CMS version 0.1
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The affected API endpoints include "admin edit submenu.php", "admin new submenu.php", and "admin edit topmenu.php" in the "admin/" directory.
Recommendations For Benja CMS version 0.1, as a temporary workaround, consider restricting access to the affected API endpoints "admin edit submenu.php", "admin new submenu.php", and "admin edit topmenu.php" until a patch is available. Avoid using the PATH INFO to inject arbitrary web script or HTML in these endpoints. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2987

Produtos afetados

Benja Cms