PT-2006-3898 · Ringlink · Ringlink
Luny
·
Published
2006-06-13
·
Updated
2018-10-18
·
CVE-2006-2991
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Ringlink version 3.2
Description
The issue allows remote attackers to inject arbitrary web script or HTML via a JavaScript URI in the SRC attribute of an IMG element. This can be achieved through manipulations in the
ringid parameter in API endpoints such as "next.cgi", "stats.cgi", or "list.cgi".Recommendations
For Ringlink version 3.2, consider restricting access to the
next.cgi, stats.cgi, and list.cgi API endpoints until a patch is available. As a temporary workaround, avoid using the ringid parameter in these endpoints to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ringlink