PT-2005-2866 · Software602 · 602Lan Suite

Published

2005-06-08

·

Updated

2008-09-05

·

CVE-2005-1909

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions 602LAN SUITE version 2004
Description The issue allows remote attackers to make it more difficult for the administrator to read portions of log files via a "<!-" sequence in an HTTP GET request in the logon, possibly due to a cross-site scripting (XSS) vulnerability.
Recommendations For 602LAN SUITE version 2004, as a temporary workaround, consider restricting access to the logon feature until a patch is available. Avoid using the HTTP GET request in the logon feature with the "<!-" sequence until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1909

Affected Products

602Lan Suite