PT-2006-5517 · Idevspot · Idevspot Phplinkexchange

S3Rv3R_Hack3R

·

Published

2006-09-13

·

Updated

2018-10-17

·

CVE-2006-4742

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IDevSpot PhpLinkExchange version 1.0
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the msg parameter in the user add.php file.
Recommendations For IDevSpot PhpLinkExchange version 1.0, consider restricting access to the user add.php file or avoiding the use of the msg parameter until a fix is available. As a temporary workaround, disabling the execution of scripts from this parameter can help mitigate the risk.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4742

Affected Products

Idevspot Phplinkexchange