PT-2011-1810 · Vodpod · Vodpod Video Gallery Plugin

John Leitch

·

Publicado

2011-10-07

·

Atualizado

2017-08-29

·

CVE-2010-4875

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Vodpod Video Gallery Plugin version 3.1.5
Description The issue is related to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary web script or HTML via the gid parameter in the vodpod-gallery/vodpod gallery thumbs.php file.
Recommendations For Vodpod Video Gallery Plugin version 3.1.5, avoid using the gid parameter in the vulnerable file until the issue is resolved. Consider temporarily restricting access to the vodpod-gallery/vodpod gallery thumbs.php file to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-4875

Produtos afetados

Vodpod Video Gallery Plugin