PT-2006-4414 · Unknown · Dragon'S Kingdom Script

Published

2006-07-13

·

Updated

2018-10-18

·

CVE-2006-3539

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Dragon's Kingdom Script version 1.0
Description The issue allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in various fields. This includes the Subject and Message fields in a do=write action in gamemail.php, multiple fields in a do=onlinechar action in index.php, the Title and Message fields in a do=new action in general.php, and unspecified fields in other Forum posts and Forum replies.
Recommendations For Dragon's Kingdom Script version 1.0, consider disabling the ability to include javascript URIs in the SRC attribute of IMG elements in all affected fields as a temporary workaround until a patch is available. Restrict access to the gamemail.php, index.php, and general.php files to minimize the risk of exploitation. Avoid using the SRC attribute in IMG elements in the affected fields until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-3539

Affected Products

Dragon'S Kingdom Script