PT-2007-1275 · Warforge · Warforge.News

Published

2007-02-12

·

Updated

2017-07-29

·

CVE-2006-6996

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions warforge.NEWS version 1.0
Description The issue allows remote attackers to inject arbitrary HTML and web script via specific parameters to certain PHP files. The vulnerable parameters include title and newspost in "newsadd.php", and name, title, and comment in "news.php".
Recommendations For warforge.NEWS version 1.0, consider restricting access to the "newsadd.php" and "newsphp" files until a fix is available, and avoid using the vulnerable parameters title, newspost, name, and comment in these files. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6996

Affected Products

Warforge.News