Tsoka · Tsoka:Cms · CVE-2010-2675
**Name of the Vulnerable Software and Affected Versions**
TSOKA:CMS versions 1.1, 1.9, 2.0
**Description**
A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML via the `id` parameter in an "articolo" action. This could potentially lead to unauthorized actions on the affected system.
**Recommendations**
For TSOKA:CMS version 1.1, update the index.php file to properly sanitize the `id` parameter.
For TSOKA:CMS version 1.9, update the index.php file to properly sanitize the `id` parameter.
For TSOKA:CMS version 2.0, update the index.php file to properly sanitize the `id` parameter.