PT-2012-2153 · Unknown · Banana Dance

Published

2012-09-15

·

Updated

2024-02-14

·

CVE-2011-5176

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Banana Dance versions prior to B.1.5
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via the q or category parameters in the "search.php" file.
Recommendations For versions prior to B.1.5, consider restricting access to the vulnerable "search.php" file until a patch is available. As a temporary workaround, avoid using the q and category parameters in the affected API endpoint until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2011-5176

Affected Products

Banana Dance