PT-2006-4078 · Mobescripts · Mobescripts Mobile Space Community
Luny
·
Published
2006-06-23
·
Updated
2017-07-20
·
CVE-2006-3183
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MobeScripts Mobile Space Community versions 2.0 and earlier
Description
The issue allows remote attackers to inject arbitrary web script or HTML via the
browse parameter, which is not filtered in the resulting error message, and multiple unspecified input fields, including those involved when updating a profile, posting comments or entries in a blog, uploading files, picture captions, and sending a private message (PM).Recommendations
For MobeScripts Mobile Space Community versions 2.0 and earlier, as a temporary workaround, consider filtering the
browse parameter and restricting input in fields related to profile updates, blog comments, file uploads, picture captions, and private messages until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mobescripts Mobile Space Community