PT-2018-3688 · Php · Php-Proxy-App+1

Eddie Tc Chang

+2

·

Publicado

2018-11-30

·

Atualizado

2022-05-14

·

CVE-2018-19785

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PHP-Proxy versions prior to 5.1.0 PHP-Proxy-App versions prior to 3.0
Description The issue is related to insufficient protection of the web page structure in the index.php component of the PHP-Proxy web proxy script, allowing a remote attacker to perform cross-site scripting (XSS) attacks via the URL field in index.php.
Recommendations For PHP-Proxy versions prior to 5.1.0, update to version 5.1.0 or later to resolve the issue. For PHP-Proxy-App versions prior to 3.0, update to version 3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the URL field in index.php to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-03193
CVE-2018-19785
GHSA-CGHJ-W42G-HQMR

Produtos afetados

Php-Proxy
Php-Proxy-App