PT-2006-1231 · Phpchamber · Phpchamber
Published
2006-01-10
·
Updated
2017-07-20
·
CVE-2006-0152
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
phpChamber versions 1.2 and earlier
Description
The issue allows remote attackers to inject arbitrary web script or HTML via the
needle parameter in the "search result.php" file. This enables attackers to execute malicious scripts on the client-side.Recommendations
For phpChamber versions 1.2 and earlier, avoid using the
needle parameter in the "search result.php" file until a fix is available. As a temporary workaround, consider restricting access to the "search result.php" file to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpchamber