PT-2006-4394 · Tbe · The Banner Engine

Published

2006-07-11

·

Updated

2018-10-18

·

CVE-2006-3519

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions The Banner Engine (tbe) version 4.0
Description The issue allows remote attackers to execute arbitrary web script or HTML. This can be achieved via the text parameter in a search action to the "/top.php" API endpoint, or through the adminpass or adminlogin parameters to the "/signup.php" API endpoint.
Recommendations For version 4.0, update the software to remove the cross-site scripting vulnerabilities, specifically ensuring that user input for the text, adminpass, and adminlogin parameters is properly sanitized to prevent arbitrary script execution. As a temporary workaround, consider restricting access to the "/top.php" and "/signup.php" API endpoints until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3519

Affected Products

The Banner Engine