PT-2005-5065 · Bitweaver · Bitweaver
Filipino Filipiciu
·
Published
2005-12-20
·
Updated
2017-07-20
·
CVE-2005-4379
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Bitweaver versions 1.1 through 1.1.1 beta
Description
The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via several parameters and API endpoints, including the
sort mode parameter to endpoints such as "fisheye/list galleries.php", "messages/message box.php", and "users/my.php"; the post id parameter to "blogs/view post.php"; the blog id parameter to "blogs/view.php"; and the search field to "users/my groups.php".Recommendations
For Bitweaver version 1.1: Avoid using the
sort mode parameter in the affected API endpoints until the issue is resolved.
For Bitweaver version 1.1.1 beta: Restrict access to the post id parameter in "blogs/view post.php" and the blog id parameter in "blogs/view.php" to minimize the risk of exploitation.
As a temporary workaround, consider disabling the search field in "users/my groups.php" until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bitweaver