PT-2004-2876 · Props · Props
Published
2004-04-30
·
Updated
2017-07-11
·
CVE-2004-1979
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PROPS version 0.6.1
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary HTML or web script via the
search string parameter in the "do search.php" file.Recommendations
For PROPS version 0.6.1, consider restricting access to the
do search.php file or avoiding the use of the search string parameter until a fix is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Props