XMB Forum Software
Not logged in [Login - Register]
Go To Bottom

Printable Version  
Author: Subject: [Security < 1.9.10] CVE-2005-2574
miqrogroove
XMB 1.9.12 Lead Developer
*********


Avatar


Posts: 443
Registered: 10-1-2002
Location: Florida
Member Is Offline

Mood: Past Three O'Clock

[*] posted on 5-9-2021 at 05:54 PM
[Security < 1.9.10] CVE-2005-2574


Bug Source: XMB 1.9.9 and older

Symptoms: Unexpected output, Javascript compromise (XSS)

Security Impact: High

ID: CVE-2005-2574

Fixed By: XMB 1.9.10 and later are not affected.

Discussion:

A variable overwrite exploit, reported to Bugtraq in 2005, was evaluated by XMB staff in 2008. This vulnerability had not been resolved and was more severe than originally described. Arguments to the 'extract' function were changed in 2008 and released with version 1.9.10 to prevent variable overwrites. These changes were also available in a service pack for version 1.9.8.

Recommendations:


View user's profile Visit user's homepage View All Posts By User

  Go To Top

Powered by XMB 1.9.12
XMB Forum Software © 2001-2021 The XMB Group
[Queries: 16] [PHP: 25.6% - SQL: 74.4%]