PT-2006-3914 · Obm · Open Business Management

Published

2006-06-13

·

Updated

2017-07-20

·

CVE-2006-3009

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Open Business Management (OBM) version 1.0.3 pl1
Description The issue allows remote attackers to inject arbitrary HTML or web script via several parameters, including tf lang, tf name, tf user, tf lastname, tf contact, tf datebefore, and tf dateafter, to various files such as "publication/publication index.php", "group/group index.php", "user/user index.php", "list/list index.php", and "company/company index.php".
Recommendations For Open Business Management (OBM) version 1.0.3 pl1, consider validating and sanitizing user input for the tf lang, tf name, tf user, tf lastname, tf contact, tf datebefore, and tf dateafter parameters to prevent arbitrary HTML or web script injection. As a temporary workaround, restrict access to the affected files, such as "publication/publication index.php", "group/group index.php", "user/user index.php", "list/list index.php", and "company/company index.php", until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3009

Affected Products

Open Business Management