vendor:
pdirl PHP Listing
by:
Vulnerability Laboratory
3,4
CVSS
MEDIUM
Cross Site Scripting
79
CWE
Product Name: pdirl PHP Listing
Affected Version From: 1.0.4
Affected Version To: 1.0.4
Patch Exists: YES
Related CWE: N/A
CPE: pdirl
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Web Application
2013
pdirl PHP Directory Listing 1.0.4 – Cross Site Scripting Web Vulnerabilities
Multiple client-side cross site scripting vulnerabilities are detected in the official pdirl PHP Directory Listing web-application. The vulnerability allows remote attackers to manipulate via GET method web-application to browser requests (client-side). The client-side cross site scripting web vulnerability is located in the vulnerable index.php file and the id path value.
Mitigation:
The vulnerability can be patched by a secure parse and encode of the vulnerable id parameter.