PT-2011-5044 · Hotaru · Hotaru Cms Search Plugin
Gjoko Krstic
·
Published
2011-12-08
·
Updated
2017-08-29
·
CVE-2011-4709
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Hotaru CMS Search plugin version 1.3
Description
The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the
SITE NAME parameter to "admin index.php", or the return and search parameters to "index.php".Recommendations
For Hotaru CMS Search plugin version 1.3, consider disabling the vulnerable parameters
SITE NAME, return, and search in the affected API endpoints "admin index.php" and "index.php" until a patch is available. Restrict access to these endpoints to minimize the risk of exploitation. Avoid using these parameters in the affected endpoints until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hotaru Cms Search Plugin