PT-2010-3482 · Repairshopr · Repairshop2
Published
2010-05-07
·
Updated
2010-05-10
·
CVE-2010-1856
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
RepairShop2 version 1.9.023 Trial
Description
The issue is related to a cross-site scripting (XSS) vulnerability. This occurs when an attacker can inject arbitrary web script or HTML into a website, potentially allowing them to steal user data or take control of the user's session. The vulnerability is specifically in the index.php file and is exploitable when the magic quotes gpc setting is disabled. The
prod parameter in a products.details action is the vulnerable point.Recommendations
For RepairShop2 version 1.9.023 Trial, consider disabling the
products.details action or restricting access to the prod parameter until a fix is available. Additionally, enabling magic quotes gpc can help mitigate this issue.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Repairshop2