PT-2005-5065 · Bitweaver · Bitweaver

Filipino Filipiciu

·

Published

2005-12-20

·

Updated

2017-07-20

·

CVE-2005-4379

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Bitweaver versions 1.1 through 1.1.1 beta
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via several parameters and API endpoints, including the sort mode parameter to endpoints such as "fisheye/list galleries.php", "messages/message box.php", and "users/my.php"; the post id parameter to "blogs/view post.php"; the blog id parameter to "blogs/view.php"; and the search field to "users/my groups.php".
Recommendations For Bitweaver version 1.1: Avoid using the sort mode parameter in the affected API endpoints until the issue is resolved. For Bitweaver version 1.1.1 beta: Restrict access to the post id parameter in "blogs/view post.php" and the blog id parameter in "blogs/view.php" to minimize the risk of exploitation. As a temporary workaround, consider disabling the search field in "users/my groups.php" until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4379

Affected Products

Bitweaver