PT-2005-1414 · Emotion · Emotion Mediapartner Web Server

Paul J Docherty

·

Published

2005-02-10

·

Updated

2017-07-11

·

CVE-2005-0336

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions EMotion MediaPartner Web Server version 5.0
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary HTML or web script. This can be demonstrated using a URL containing .. sequences and HTML, resulting in a directory browsing page that does not properly filter the HTML.
Recommendations For EMotion MediaPartner Web Server version 5.0, consider implementing proper HTML filtering for the directory browsing page to prevent arbitrary HTML or web script injection. As a temporary workaround, restrict access to the directory browsing functionality until a proper fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0336

Affected Products

Emotion Mediapartner Web Server