PT-2007-6709 · Omnistar · Omnistar Live
Published
2007-10-30
·
Updated
2018-10-15
·
CVE-2007-5724
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Omnistar Live (affected versions not specified)
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. Specifically, the
category id parameter to the "users/kb.php" endpoint and possibly the Email Box field in "profile.php" are affected.Recommendations
For Omnistar Live, consider disabling the
category id parameter in the "users/kb.php" endpoint and restricting access to the Email Box field in "profile.php" until a fix is available. Avoid using the category id parameter in the "users/kb.php" endpoint and the Email Box field in "profile.php" to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Omnistar Live