PT-2011-1740 · Open Cit · Open It Overlook
Eliteman
·
Publicado
2011-04-27
·
Atualizado
2017-08-17
·
CVE-2010-4792
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OPEN IT OverLook version 5.0
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the
frame parameter in the title.php file.Recommendations
For OPEN IT OverLook version 5.0, consider restricting access to the title.php file or disabling the
frame parameter to minimize the risk of exploitation until a patch is available.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Open It Overlook