PT-2005-5051 · Flip · Flip
Published
2005-12-20
·
Updated
2011-03-08
·
CVE-2005-4365
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FLIP version 0.9.0.1029
Description
The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the
name parameter in "text.php" or the frame parameter in "forum.php".Recommendations
For FLIP version 0.9.0.1029, consider restricting access to the
text.php and forum.php endpoints until a fix is available. As a temporary workaround, avoid using the name and frame parameters in these endpoints to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flip