PT-2006-3462 · Hiox · Hiox Guest Book
Luny
·
Published
2006-05-22
·
Updated
2018-10-18
·
CVE-2006-2515
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Hiox Guestbook version 3.1
Description
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the input forms for signing the guestbook. This could potentially lead to unauthorized actions on the website.
Recommendations
For Hiox Guestbook version 3.1, update the input validation and sanitization in the index.php file to prevent the injection of malicious scripts or HTML. As a temporary workaround, consider disabling the guestbook signing feature until a patch is available. Restrict access to the index.php file to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hiox Guest Book