vendor:
Dreamweaver MX
by:
SecurityFocus
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: Dreamweaver MX
Affected Version From: Dreamweaver MX
Affected Version To: Dreamweaver MX
Patch Exists: No
Related CWE: N/A
CPE: Dreamweaver MX
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Cross-Site Scripting in Macromedia Dreamweaver MX PHP Authentication Suite
A cross-site-scripting vulnerability has been reported to affect PHP authentication functions used in PHP access control pages created with the Macromedia Dreamweaver MX PHP Authentication Suite. An attacker may exploit this condition to execute arbitrary HTML code in the browser of an unsuspecting user.
Mitigation:
Ensure that user-supplied input is properly validated and filtered before being used in the application.