PT-2006-3671 · Osic · Open Searchable Image Catalogue

Nenad Jovanovic

·

Published

2006-06-01

·

Updated

2018-10-18

·

CVE-2006-2751

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Open Searchable Image Catalogue (OSIC) versions 0.7.0.1 and earlier
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web scripts or HTML via the item list parameter in the "search.php" endpoint. This could potentially lead to unauthorized actions on the affected system.
Recommendations For OSIC versions 0.7.0.1 and earlier, as a temporary workaround, consider restricting access to the "search.php" endpoint or sanitizing the item list parameter to prevent malicious input until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2751

Affected Products

Open Searchable Image Catalogue