PT-2005-1580 · Pblang · Pblang

Raven

·

Published

2005-02-23

·

Updated

2016-10-18

·

CVE-2005-0526

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PBLang version 4.65
Description The issue allows remote attackers to inject arbitrary web script or HTML, potentially leading to cross-site scripting (XSS) attacks. This can be achieved through various means, including the search string to the "search.php" endpoint, the subject of a private message processed by "pm.php", or the body of a private message processed by "pmpshow.php".
Recommendations For PBLang version 4.65, consider disabling the search functionality in "search.php", restricting user input in the subject and body of private messages processed by "pm.php" and "pmpshow.php" respectively, until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0526

Affected Products

Pblang