PT-2006-2358 · Musicbox · Musicbox

Published

2006-03-22

·

Updated

2018-10-18

·

CVE-2006-1349

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Musicbox version 2.3 Beta 2
Description The issue allows remote attackers to inject arbitrary web script or HTML via specific parameters in certain PHP files. This can be achieved by manipulating the id, type, and show parameters in a top action in index.php, or the message1 parameter in cart.php.
Recommendations For Musicbox version 2.3 Beta 2, as a temporary workaround, consider restricting access to the index.php and cart.php files until a patch is available. Avoid using the id, type, show, and message1 parameters in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1349

Affected Products

Musicbox