PT-2005-1705 · Mercury · Mercuryboard

Published

2005-03-07

·

Updated

2008-09-05

·

CVE-2005-0662

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MercuryBoard version 1.1.2
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the Avatar field in index.php. This could potentially lead to unauthorized actions on the affected system.
Recommendations For MercuryBoard version 1.1.2, consider validating and sanitizing user input for the Avatar field to prevent the injection of malicious scripts. As a temporary workaround, restrict access to the Avatar field until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0662

Affected Products

Mercuryboard