PT-2004-3560 · Endonesia · Endonesia
Published
2004-12-31
·
Updated
2017-07-29
·
CVE-2004-2670
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
eNdonesia version 8.3
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities in the mod.php file of eNdonesia. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. This can be achieved through two main vectors: (1) the
mod parameter in a 'viewcat' operation or (2) the query parameter in a 'search' operation within the publisher module.Recommendations
For eNdonesia version 8.3, consider disabling the mod.php file or restricting access to the 'viewcat' and 'search' operations in the publisher module until a patch is available. Avoid using the
mod and query parameters in these operations to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Endonesia