PT-2005-4589 · Kplaylist · Kplaylist

Published

2005-11-26

·

Updated

2011-03-08

·

CVE-2005-3841

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions kPlaylist versions 1.6 (build 400) and possibly other versions
Description The issue allows remote attackers to inject arbitrary web script or HTML via the searchfor search parameter. This can lead to cross-site scripting (XSS) attacks.
Recommendations For version 1.6 (build 400), avoid using the searchfor parameter in the search functionality until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3841

Affected Products

Kplaylist