PT-2005-3560 · Land Down Under · Land Down Under (Ldu) 800
Bl2K
+1
·
Published
2005-08-23
·
Updated
2024-08-07
·
CVE-2005-2674
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Land Down Under (LDU) 800
Description
Multiple cross-site scripting (XSS) vulnerabilities allow remote attackers to inject arbitrary web script or HTML via the
c or m parameters to "index.php" or the w parameter to "journal.php". The vendor has disputed this issue, stating that the variables are properly sanitized and no LDU version is affected.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Land Down Under (Ldu) 800