PT-2011-2620 · Janrain · Janrain Engage

Publicado

2011-02-04

·

Atualizado

2017-08-17

·

CVE-2011-0771

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Janrain Engage module versions 6.x-1.3
Description The issue allows remote authenticated users to conduct cross-site scripting (XSS) attacks and possibly execute arbitrary PHP code by causing a crafted avatar to be downloaded from an external login provider site, due to the lack of validation for profile image files.
Recommendations For Janrain Engage module version 6.x-1.3, consider validating profile image files to prevent cross-site scripting (XSS) attacks and the possible execution of arbitrary PHP code. As a temporary workaround, restrict the ability to download avatars from external login provider sites until a proper fix is applied.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-0771

Produtos afetados

Janrain Engage