PT-2009-4969 · Verlihub · Verlihub Control Panel
Published
2009-07-22
·
Updated
2009-07-22
·
CVE-2009-2569
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Verlihub Control Panel (VHCP) version 1.7e
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. This can be achieved via the
nick parameter in a login action to "index.php" or via the URI in a news request to "index.html".Recommendations
For Verlihub Control Panel (VHCP) version 1.7e, consider disabling the login functionality in "index.php" and restricting access to "index.html" until a patch is available. Avoid using the
nick parameter in the login action to "index.php" to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Verlihub Control Panel