PT-2003-1607 · Bandmin · Bandmin
Silent Needle
·
Published
2003-06-11
·
Updated
2016-10-18
·
CVE-2003-0416
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Bandmin version 1.4
Description:
A cross-site scripting (XSS) issue exists, allowing remote attackers to insert arbitrary HTML or script via specific parameters in certain actions. The vulnerable parameters include the
year parameter in a "showmonth" action, the month parameter in a "showmonth" action, and the host parameter in a "showhost" action.Recommendations:
For Bandmin version 1.4, as a temporary workaround, consider restricting access to the index.cgi file until a patch is available. Avoid using the
year, month, and host parameters in the affected actions until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bandmin