PT-2006-3898 · Ringlink · Ringlink

Luny

·

Published

2006-06-13

·

Updated

2018-10-18

·

CVE-2006-2991

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Ringlink version 3.2
Description The issue allows remote attackers to inject arbitrary web script or HTML via a JavaScript URI in the SRC attribute of an IMG element. This can be achieved through manipulations in the ringid parameter in API endpoints such as "next.cgi", "stats.cgi", or "list.cgi".
Recommendations For Ringlink version 3.2, consider restricting access to the next.cgi, stats.cgi, and list.cgi API endpoints until a patch is available. As a temporary workaround, avoid using the ringid parameter in these endpoints to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2991

Affected Products

Ringlink