CVE-2018-5705

Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:reservo:image_hosting:1.6:*:*:*:*:*:*:*

Information

Published : 2018-01-24 09:29

Updated : 2018-02-09 09:55


NVD link : CVE-2018-5705

Mitre link : CVE-2018-5705


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

reservo

  • image_hosting