PT-2006-5867 · Ph03Y3Nk · Ph03Y3Nk Just Another Flat File (Jaf) Cms
Nanoymaster
·
Published
2006-10-02
·
Updated
2018-10-17
·
CVE-2006-5129
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ph03y3nk just another flat file (JAF) CMS version 4.0 RC1
Description
The issue allows remote attackers to inject arbitrary web script or HTML, potentially leading to cross-site scripting (XSS) attacks. This can be achieved via the
message parameter in the /module/shout/jafshout.php endpoint, and possibly other parameters. Additionally, the issue can be exploited through the message body in a forum post in the /module/forum/topicwin.php endpoint, related to the name, email, title, date, ldate, and lname variables.Recommendations
For ph03y3nk just another flat file (JAF) CMS version 4.0 RC1, consider disabling the shoutbox functionality in
module/shout/jafshout.php and restricting user input in the forum post functionality in module/forum/topicwin.php to minimize the risk of exploitation. Avoid using the message parameter in the /module/shout/jafshout.php endpoint and the name, email, title, date, ldate, and lname variables in the /module/forum/topicwin.php endpoint until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ph03Y3Nk Just Another Flat File (Jaf) Cms