PT-2009-4597 · Translucid · Translucid
Intern0T
+2
·
Published
2009-06-22
·
Updated
2017-09-29
·
CVE-2009-2145
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
transLucid version 1.75
Description
The issue allows remote attackers to inject arbitrary web script or HTML via the
NodeID and action parameters to the default URI, and the NodeID parameter to the default URI for the admin section. Additionally, remote authenticated users can inject arbitrary web script or HTML via the Title (aka page name) and Url fields in a new or modified page.Recommendations
For transLucid version 1.75, consider disabling the
NodeID and action parameters to the default URI, and the NodeID parameter to the default URI for the admin section, until a patch is available. Also, restrict access to the Title and Url fields in new or modified pages to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Translucid