PT-2008-5664 · Phlatline · Phlatline'S Personal Information Manager
Beyazkurt
·
Published
2008-10-03
·
Updated
2017-09-29
·
CVE-2008-4426
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Phlatline's Personal Information Manager (pPIM) version 1.0
Description:
The issue is related to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary web script or HTML via the
date parameter in a new action. This occurs in the events.php file.Recommendations:
For version 1.0, avoid using the
date parameter in the new action until the issue is resolved. As a temporary workaround, consider restricting access to the events.php file to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phlatline'S Personal Information Manager