PT-2006-4221 · Hostflow · Hostflow
Published
2006-06-30
·
Updated
2017-07-20
·
CVE-2006-3328
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Hostflow version 2.2.1-15
Description
The issue allows remote attackers to steal and replay authentication credentials. This is possibly due to a cross-site scripting (XSS) vulnerability or a leak of credentials in referer URLs, where an attacker can use an IMG tag in the
desc parameter (Ticket Description field) that points to a URL capturing referer URLs.Recommendations
For Hostflow version 2.2.1-15, avoid using the
desc parameter in the new ticket.cgi until a fix is available, and restrict access to the new ticket.cgi to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hostflow