PT-2008-5267 · Opendb · Opendb

CVE-2008-3937

·

Publicado

2008-09-05

·

Atualizado

2025-04-03

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenDb version 1.0.6
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the user id parameter in an edit action to "user admin.php", the title parameter to "listings.php", and the redirect url parameter to "user profile.php".
Recommendations For OpenDb version 1.0.6, avoid using the user id parameter in the edit action to "user admin.php", the title parameter to "listings.php", and the redirect url parameter to "user profile.php" until a fix is available. Consider restricting access to these parameters to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3937

Produtos afetados

Opendb