PT-2011-5044 · Hotaru · Hotaru Cms Search Plugin
Gjoko Krstic
·
Publicado
2011-12-08
·
Atualizado
2017-08-29
·
CVE-2011-4709
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Hotaru CMS Search plugin version 1.3
Description
The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the
SITE NAME parameter to "admin index.php", or the return and search parameters to "index.php".Recommendations
For Hotaru CMS Search plugin version 1.3, consider disabling the vulnerable parameters
SITE NAME, return, and search in the affected API endpoints "admin index.php" and "index.php" until a patch is available. Restrict access to these endpoints to minimize the risk of exploitation. Avoid using these parameters in the affected endpoints until the issue is resolved.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Hotaru Cms Search Plugin