PT-2007-7373 · Neuron · Neuron News
Black.Shadowes
+1
·
Published
2007-12-27
·
Updated
2018-10-15
·
CVE-2007-6541
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
neuron news version 1.0
Description
The issue allows remote attackers to inject arbitrary web script or HTML via specific parameters in certain actions. This can be achieved by manipulating the
topic parameter in a "viewtopic" action, or the newsyear or newsmonth parameters in a "newsarchive" action to the default URI in patch/.Recommendations
For neuron news version 1.0, as a temporary workaround, consider restricting access to the "viewtopic" and "newsarchive" actions until a patch is available. Avoid using the parameters
topic, newsyear, and newsmonth in the affected actions to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Neuron News