PT-2012-3009 · Sphinx · Sphinx Software Mobile Web Server

Published

2012-02-07

·

Updated

2017-08-29

·

CVE-2012-1005

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Sphinx Software Mobile Web Server version 3.1.2.47
Description The issue allows remote attackers to inject arbitrary web script or HTML via the comment parameter to a blog. This can be demonstrated using specific blog files, such as 'Blog/MyFirstBlog.txt' or 'Blog/AboutSomething.txt'.
Recommendations For Sphinx Software Mobile Web Server version 3.1.2.47, avoid using the comment parameter in blog endpoints until the issue is resolved. As a temporary workaround, consider restricting access to blog files, such as 'Blog/MyFirstBlog.txt' and 'Blog/AboutSomething.txt', to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1005

Affected Products

Sphinx Software Mobile Web Server