PT-2010-4244 · Rightinpoint · Rightinpoint Lyrics Script
Publicado
2010-07-13
·
Atualizado
2010-07-15
·
CVE-2010-2722
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
RightInPoint Lyrics Script version 3.0
Description
A cross-site scripting (XSS) issue exists due to improper handling of the
artist id parameter in a forced SQL error message, allowing remote attackers to inject arbitrary web script or HTML.Recommendations
For version 3.0, ensure proper handling and sanitization of the
artist id parameter to prevent XSS attacks. As a temporary workaround, consider restricting access to the vulnerable index.php file until a proper fix is applied.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Rightinpoint Lyrics Script