PT-2009-1909 · Abk Soft · Abledating
Published
2009-03-06
·
Updated
2018-10-11
·
CVE-2008-6439
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
ABK-Soft AbleDating version 2.4
Description:
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the
keyword parameter in the "search results.php" file.Recommendations:
For version 2.4, consider restricting access to the
search results.php file or avoiding the use of the keyword parameter until a fix is available. As a temporary workaround, disabling the execution of scripts in the search results.php file may help mitigate the risk.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abledating