PT-2007-2935 · Php · Phpx

Published

2007-03-20

·

Updated

2018-10-16

·

CVE-2007-1551

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpx version 3.5.15
Description The issue allows remote attackers to inject arbitrary web script or HTML, which can lead to cross-site scripting (XSS) attacks. This can occur via the signature in a user's profile or through the search.php page, specifically by manipulating the signature variable in "dans profile" or by exploiting the search.php endpoint.
Recommendations For phpx version 3.5.15, update to a version that fixes the XSS vulnerabilities. As a temporary workaround, consider restricting user input in the signature field and limiting access to the search.php page until a patch is available. Avoid using potentially malicious input in the signature variable or the search.php endpoint to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1551

Affected Products

Phpx