PT-2006-2306 · Milkeyway · Milkeyway Captive Portal

Ascii

·

Published

2006-03-19

·

Updated

2018-10-18

·

CVE-2006-1290

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Milkeyway Captive Portal versions 0.1 through 0.1.1
Description The issue allows remote attackers to inject arbitrary web script or HTML via vulnerable parameters in certain PHP files. Specifically, the parameters ipAddress, act, username, and other unspecified parameters in authuser.php, as well as username and other unspecified parameters in userstatistics.php, are affected.
Recommendations For Milkeyway Captive Portal versions 0.1 through 0.1.1, consider restricting access to the authuser.php and userstatistics.php files until a patch is available. As a temporary workaround, avoid using the parameters ipAddress, act, and username in the affected API endpoints. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1290

Affected Products

Milkeyway Captive Portal