PT-2005-1395 · Alt N · Alt-N Webadmin
David Alonso Pérez
·
Published
2005-01-28
·
Updated
2017-07-11
·
CVE-2005-0317
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Alt-N WebAdmin version 3.0.4
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the
user parameter in the useredit account.wdm file.Recommendations
For Alt-N WebAdmin version 3.0.4, consider restricting access to the useredit account.wdm file until a patch is available. As a temporary workaround, avoid using the
user parameter in the affected file to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt-N Webadmin