PT-2004-3057 · Tutos · Tutos
Joxean Koret
·
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2162
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
TUTOS version 1.1
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The injection can occur via two main avenues: the search field of the Address Module or the
t parameter to "app new.php".Recommendations
For TUTOS version 1.1, consider disabling the search field in the Address Module and restricting access to the "app new.php" endpoint to minimize the risk of exploitation. Avoid using the
t parameter in the "app new.php" endpoint until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tutos