PT-2008-5664 · Phlatline · Phlatline'S Personal Information Manager

Beyazkurt

·

Published

2008-10-03

·

Updated

2017-09-29

·

CVE-2008-4426

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Phlatline's Personal Information Manager (pPIM) version 1.0
Description: The issue is related to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary web script or HTML via the date parameter in a new action. This occurs in the events.php file.
Recommendations: For version 1.0, avoid using the date parameter in the new action until the issue is resolved. As a temporary workaround, consider restricting access to the events.php file to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4426

Affected Products

Phlatline'S Personal Information Manager