PT-2003-1607 · Bandmin · Bandmin

Silent Needle

·

Published

2003-06-11

·

Updated

2016-10-18

·

CVE-2003-0416

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Bandmin version 1.4
Description: A cross-site scripting (XSS) issue exists, allowing remote attackers to insert arbitrary HTML or script via specific parameters in certain actions. The vulnerable parameters include the year parameter in a "showmonth" action, the month parameter in a "showmonth" action, and the host parameter in a "showhost" action.
Recommendations: For Bandmin version 1.4, as a temporary workaround, consider restricting access to the index.cgi file until a patch is available. Avoid using the year, month, and host parameters in the affected actions until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0416

Affected Products

Bandmin