PT-2006-2306 · Milkeyway · Milkeyway Captive Portal
Ascii
·
Published
2006-03-19
·
Updated
2018-10-18
·
CVE-2006-1290
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Milkeyway Captive Portal versions 0.1 through 0.1.1
Description
The issue allows remote attackers to inject arbitrary web script or HTML via vulnerable parameters in certain PHP files. Specifically, the parameters
ipAddress, act, username, and other unspecified parameters in authuser.php, as well as username and other unspecified parameters in userstatistics.php, are affected.Recommendations
For Milkeyway Captive Portal versions 0.1 through 0.1.1, consider restricting access to the
authuser.php and userstatistics.php files until a patch is available. As a temporary workaround, avoid using the parameters ipAddress, act, and username in the affected API endpoints. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Milkeyway Captive Portal