PT-2010-4244 · Rightinpoint · Rightinpoint Lyrics Script
Published
2010-07-13
·
Updated
2010-07-15
·
CVE-2010-2722
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
RightInPoint Lyrics Script version 3.0
Description
A cross-site scripting (XSS) issue exists due to improper handling of the
artist id parameter in a forced SQL error message, allowing remote attackers to inject arbitrary web script or HTML.Recommendations
For version 3.0, ensure proper handling and sanitization of the
artist id parameter to prevent XSS attacks. As a temporary workaround, consider restricting access to the vulnerable index.php file until a proper fix is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rightinpoint Lyrics Script