PT-2006-5707 · Maxdev · Maxdev Md-Pro

Published

2006-09-23

·

Updated

2024-02-14

·

CVE-2006-4964

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MAXdev MDPro versions prior to 1.0.76 (updated before 20060918)
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML. This is achieved through vectors that bypass the XSS protection mechanisms of the pnVarCleanFromInput function and unspecified vectors related to the AntiCracker.
Recommendations For MAXdev MDPro versions prior to 1.0.76, update to a version released after 20060918 to resolve the issue. As a temporary workaround, consider restricting input to prevent bypassing the XSS protection mechanisms until a patch is available.

Fix

Related Identifiers

CVE-2006-4964

Affected Products

Maxdev Md-Pro