Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Shen139

Researcher fromBADROOT SECURITY GROUP
#51017of 53,630
4.3Total CVSS
Vulnerabilities · 1
PT-2005-3095
4.3
2005-07-06
Unknown · Autoindex Php Script · CVE-2005-2163
Name of the Vulnerable Software and Affected Versions: AutoIndex PHP Script version 1.5.2 Description: A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the `search` parameter in the "index.php" file. Recommendations: For AutoIndex PHP Script version 1.5.2, consider validating and sanitizing user input for the `search` parameter to prevent XSS attacks. As a temporary workaround, restrict access to the "index.php" file until a patch is available.