PT-2006-4078 · Mobescripts · Mobescripts Mobile Space Community

Luny

·

Published

2006-06-23

·

Updated

2017-07-20

·

CVE-2006-3183

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MobeScripts Mobile Space Community versions 2.0 and earlier
Description The issue allows remote attackers to inject arbitrary web script or HTML via the browse parameter, which is not filtered in the resulting error message, and multiple unspecified input fields, including those involved when updating a profile, posting comments or entries in a blog, uploading files, picture captions, and sending a private message (PM).
Recommendations For MobeScripts Mobile Space Community versions 2.0 and earlier, as a temporary workaround, consider filtering the browse parameter and restricting input in fields related to profile updates, blog comments, file uploads, picture captions, and private messages until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3183

Affected Products

Mobescripts Mobile Space Community