PT-2010-5636 · Debian · Tdiary

Publicado

1970-01-01

·

Atualizado

2010-03-03

·

CVE-2010-0726

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions tdiary versions 2.2.2 and earlier
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML, possibly related to the plugin tb url and plugin tb excerpt parameters. Multiple vulnerabilities in the tdiary package of Debian GNU/Linux can be exploited remotely, potentially disrupting the integrity of protected information.
Recommendations For tdiary versions 2.2.2 and earlier, consider disabling the tb-send.rb plugin until a patch is available. Restrict access to the plugin tb url and plugin tb excerpt parameters to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-01595
BDU:2015-01596
BDU:2015-01597
BDU:2015-01598
BDU:2015-01599
CVE-2010-0726
DSA-2009-1

Produtos afetados

Tdiary