6.8

CVE-2005-0085

Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.

Data is provided by the National Vulnerability Database (NVD)
HtdigHtdig Version3.1.5
HtdigHtdig Version3.1.5_7
HtdigHtdig Version3.1.5_8
HtdigHtdig Version3.1.6
HtdigHtdig Version3.2.0
HtdigHtdig Version3.2.0b2
HtdigHtdig Version3.2.0b3
HtdigHtdig Version3.2.0b4
HtdigHtdig Version3.2.0b5
HtdigHtdig Version3.2.0b6
MandrakesoftMandrake Linux Version10.0
MandrakesoftMandrake Linux Version10.0 Editionamd64
MandrakesoftMandrake Linux Version10.1
MandrakesoftMandrake Linux Version10.1 Editionx86_64
MandrakesoftMandrake Linux Corporate Server Version2.1 Editionx86_64
MandrakesoftMandrake Linux Corporate Server Version3.0 Editionx86_64
RedhatFedora Core Versioncore_3.0
SuseSuse Linux Version8.0
SuseSuse Linux Version8.0 Editioni386
SuseSuse Linux Version8.1
SuseSuse Linux Version8.2
SuseSuse Linux Version9.0
SuseSuse Linux Version9.0 Editionx86_64
SuseSuse Linux Version9.1
SuseSuse Linux Version9.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.73% 0.883
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P