PT-2009-4668 · Php · Phpcollegeexchange

Cracker

·

Publicado

2009-06-25

·

Atualizado

2017-09-19

·

CVE-2009-2219

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpCollegeExchange version 0.1.5c
Description The issue allows remote attackers to inject arbitrary web script or HTML, potentially leading to cross-site scripting (XSS) attacks. This can be achieved via the SESSION[handle] parameter to various PHP files, including home.php, books/allbooks.php, or books/home.php, or through the home parameter to files such as i head.php, i nav.php, allbooks.php, home.php, or i nav.php in the books/ directory. API Endpoints and variables involved include:
  • SESSION[handle] parameter
  • home parameter to endpoints like home.php, books/allbooks.php, books/home.php, i head.php, i nav.php, allbooks.php, and home.php in books/.
Recommendations For phpCollegeExchange version 0.1.5c, as a temporary workaround, consider validating and sanitizing the SESSION[handle] and home parameters to prevent injection of malicious scripts. Restrict access to the affected PHP files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2219

Produtos afetados

Phpcollegeexchange