PT-2007-7320 · Lineshout · Lineshout
Published
2007-12-20
·
Updated
2017-08-08
·
CVE-2007-6486
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
LineShout version 1.0
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The injection can occur via the
username (also referred to as nickname) or message parameter in the shout.php file, also known as the shoutbox.Recommendations
For LineShout version 1.0, consider restricting the input for the
username and message parameters to prevent the injection of malicious scripts until a fix is available. As a temporary workaround, disabling the shoutbox functionality in shout.php could minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lineshout