PT-2006-2414 · Sweetsuite.Net · Sweetsuite.Net Content Management System

Published

2006-03-28

·

Updated

2017-07-20

·

CVE-2006-1405

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SweetSuite.NET Content Management System (ssCMS) versions 2.1.0 and earlier
Description The issue is related to a cross-site scripting (XSS) vulnerability. It affects the search.aspx page in the SweetSuite.NET Content Management System (ssCMS), allowing remote attackers to inject arbitrary web script or HTML via the keywords parameter.
Recommendations For versions 2.1.0 and earlier, update to a version later than 2.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the search.aspx page or avoiding the use of the keywords parameter until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1405

Affected Products

Sweetsuite.Net Content Management System