PT-2005-4542 · Phpadsnew · Phppgads+1

Toni Koivunen

·

Published

2005-11-24

·

Updated

2016-10-18

·

CVE-2005-3791

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpAdsNew versions prior to 2.0.6 phpPgAds versions prior to 2.0.6
Description The issue allows remote attackers to inject arbitrary HTML headers, potentially leading to security breaches. This is achieved via the adclick.php endpoint and possibly other unspecified vectors.
Recommendations For phpAdsNew versions prior to 2.0.6, update to a version later than 2.0.6. For phpPgAds versions prior to 2.0.6, update to a version later than 2.0.6. As a temporary workaround, consider restricting access to the adclick.php endpoint until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3791

Affected Products

Phpadsnew
Phppgads