PT-2006-2426 · Caloris Planitia · Caloris Planitia Online Quiz System
Published
2006-03-28
·
Updated
2017-07-20
·
CVE-2006-1417
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Caloris Planitia Online Quiz System version 1.0
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. Specifically, the
exam parameter in prequiz.asp and the msg parameter in student.asp are vulnerable.Recommendations
For Caloris Planitia Online Quiz System version 1.0, consider disabling the
exam parameter in prequiz.asp and the msg parameter in student.asp to minimize the risk of exploitation until a patch is available. Restrict access to prequiz.asp and student.asp to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Caloris Planitia Online Quiz System