PT-2002-2671 · Phprank · Phprank
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-1950
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
phpRank version 1.8
Description
The issue is related to a cross-site scripting (XSS) vulnerability. This allows remote attackers to inject arbitrary web script or HTML. Specifically, the vulnerability can be exploited through the
email parameter of "add.php" or the banurl parameter, which is the banner URL in the main list.Recommendations
For phpRank version 1.8, as a temporary workaround, consider validating and sanitizing user input for the
email parameter in "add.php" and the banurl parameter to prevent malicious script injections. Restrict access to "add.php" and limit the ability to set the banner URL to trusted users until a fix is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phprank