PT-2009-2680 · Mostlyce+1 · Mostlyce+1

Publicado

2009-09-11

·

Atualizado

2018-10-11

·

CVE-2008-7213

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MOStlyCE versions prior to 2.4 Mambo versions 4.6.3 and earlier
Description The issue is related to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary web script or HTML via the Command parameter in the /connectors/php/connector.php file.
Recommendations For MOStlyCE versions prior to 2.4, update to version 2.4 or later. For Mambo versions 4.6.3 and earlier, consider upgrading to a version later than 4.6.3 to mitigate the risk. As a temporary workaround, consider restricting access to the vulnerable connector.php file until a patch is available. Avoid using the Command parameter in the affected API endpoint until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-7213

Produtos afetados

Mostlyce
Mambo