PT-2006-3914 · Obm · Open Business Management
Published
2006-06-13
·
Updated
2017-07-20
·
CVE-2006-3009
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Open Business Management (OBM) version 1.0.3 pl1
Description
The issue allows remote attackers to inject arbitrary HTML or web script via several parameters, including
tf lang, tf name, tf user, tf lastname, tf contact, tf datebefore, and tf dateafter, to various files such as "publication/publication index.php", "group/group index.php", "user/user index.php", "list/list index.php", and "company/company index.php".Recommendations
For Open Business Management (OBM) version 1.0.3 pl1, consider validating and sanitizing user input for the
tf lang, tf name, tf user, tf lastname, tf contact, tf datebefore, and tf dateafter parameters to prevent arbitrary HTML or web script injection. As a temporary workaround, restrict access to the affected files, such as "publication/publication index.php", "group/group index.php", "user/user index.php", "list/list index.php", and "company/company index.php", until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open Business Management