PT-2003-2451 · Adelix · Adelix Censornet
Richard Maudsley
·
Published
2003-12-31
·
Updated
2017-07-29
·
CVE-2003-1506
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Adelix CensorNet versions 3.0 through 3.2
Description
A cross-site scripting (XSS) issue allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the
DENIEDURL parameter. This enables attackers to perform actions on behalf of other users.Recommendations
For Adelix CensorNet versions 3.0 through 3.2, avoid using the
DENIEDURL parameter until a fix is available. As a temporary workaround, consider restricting access to the dansguardian.pl script to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adelix Censornet