PT-2006-5716 · Perpetual Motion Interactive Systems · Dotnetnuke

CVE-2006-4973

·

Publicado

2006-09-25

·

Atualizado

2024-02-14

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Perpetual Motion Interactive Systems DotNetNuke versions prior to 3.3.5 Perpetual Motion Interactive Systems DotNetNuke versions 4.x prior to 4.3.5
Description A cross-site scripting issue allows remote attackers to inject arbitrary HTML via the error parameter in the Default.aspx file.
Recommendations For versions prior to 3.3.5, update to version 3.3.5 or later. For versions 4.x prior to 4.3.5, update to version 4.3.5 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4973

Produtos afetados

Dotnetnuke