PT-2004-3057 · Tutos · Tutos

Joxean Koret

·

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2162

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions TUTOS version 1.1
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The injection can occur via two main avenues: the search field of the Address Module or the t parameter to "app new.php".
Recommendations For TUTOS version 1.1, consider disabling the search field in the Address Module and restricting access to the "app new.php" endpoint to minimize the risk of exploitation. Avoid using the t parameter in the "app new.php" endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2162
DSA-980-1

Affected Products

Tutos