Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.100368
Categoría:Web application abuses
Título:Power Phlogger Cross-site Scripting Vulnerability
Resumen:Power Phlogger is prone to a cross-site scripting vulnerability; because the application fails to properly sanitize user-supplied input.
Descripción:Summary:
Power Phlogger is prone to a cross-site scripting vulnerability
because the application fails to properly sanitize user-supplied input.

Vulnerability Impact:
Attackers can exploit this issue to steal cookie-based authentication
credentials or to control how the site is rendered to the user.

Affected Software/OS:
Power Phlogger 2.2.5 is vulnerable, other versions may also be
affected.

Solution:
No known solution was made available for at least one year
since the disclosure of this vulnerability. Likely none will be provided anymore.
General solution options are to upgrade to a newer release, disable respective features,
remove the product or replace the product by another one.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2009-4253
BugTraq ID: 37150
http://www.securityfocus.com/bid/37150
http://www.websecurity.com.ua/1845
http://secunia.com/advisories/30423
XForce ISS Database: powerphlogger-dspstats-xss(54541)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54541
CopyrightCopyright (C) 2009 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.