PT-2005-4307 · Spymac · Spymac Webos
Lostmon
·
Published
2005-11-06
·
Updated
2011-09-13
·
CVE-2005-3511
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Spymac Web OS version 4.0
Description
The issue allows remote attackers to inject arbitrary web script or HTML, potentially leading to cross-site scripting (XSS) attacks. This can be achieved through various parameters in the blogs and notes modules. In the blogs module, vulnerable parameters include
curr in index.php, inspire, system, title in blog newentry.php, entry in blog newentry comment.php and blog edit entry.php, and caldate in blog.php. In the notes module, vulnerable parameters include forwardid in a noteform action, del folder in a delete folder action, isread, dateorder, subjectorder, curr, fromorder, action, ppp, totalreplies in an Inbox action, totalnotes, and touserid in a noteform action.Recommendations
For Spymac Web OS version 4.0, consider disabling the blogs and notes modules until a patch is available. Restrict access to the vulnerable parameters, such as
curr, inspire, system, title, entry, caldate, forwardid, del folder, isread, dateorder, subjectorder, fromorder, action, ppp, totalreplies, totalnotes, and touserid, to minimize the risk of exploitation. Avoid using these parameters in the affected API endpoints until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spymac Webos