PT-2008-3984 · Actualanalyzer · Actualanalyzer Gold+4
Published
2008-06-03
·
Updated
2018-10-11
·
CVE-2008-2527
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ActualAnalyzer Server versions 8.37 and earlier
ActualAnalyzer Gold versions 7.74 and earlier
ActualAnalyzer Pro versions 6.95 and earlier
ActualAnalyzer Lite versions 2.78 and earlier
Description
The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability allows remote attackers to inject arbitrary web script or HTML via the
language parameter in the view.php file.Recommendations
For ActualAnalyzer Server versions 8.37 and earlier, update to a version later than 8.37.
For ActualAnalyzer Gold versions 7.74 and earlier, update to a version later than 7.74.
For ActualAnalyzer Pro versions 6.95 and earlier, update to a version later than 6.95.
For ActualAnalyzer Lite versions 2.78 and earlier, update to a version later than 2.78.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Actualanalyzer Gold
Actualanalyzer Lite
Actualanalyzer Pro
Actualanalyzer Server
View.Php