PT-2005-3762 · Cjlinkout · Cjlinkout
Psymera
·
Published
2005-09-14
·
Updated
2016-10-18
·
CVE-2005-2900
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
CjLinkOut version 1.0
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the
123 parameter in the top.php file. This could potentially lead to unauthorized actions on the affected system.Recommendations
For CjLinkOut version 1.0, consider restricting access to the top.php file or avoiding the use of the
123 parameter until a fix is available. As a temporary workaround, disabling the execution of scripts from this parameter may help mitigate the risk.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cjlinkout