5.8
CVE-2005-1162
- EPSS 5.57%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:12:33
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in OneWorldStore allow remote attackers to inject arbitrary web script or HTML via the (1) sEmail parameter to owContactUs.asp, (2) bSub parameter to owListProduct.asp, or the (3) Name, (4) Email, or (5) Comment fields in owProductDetail.asp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.57% | 0.919 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
http://marc.info/?l=bugtraq&m=111352017704126&w=2
http://secunia.com/advisories/14969
http://securitytracker.com/id?1013720
http://www.oneworldstore.com/support_security_issue_updates.asp#April_15_2005_DCrab
http://www.osvdb.org/15521
http://www.osvdb.org/15522
http://www.osvdb.org/15523
http://www.securityfocus.com/bid/13184
http://www.securityfocus.com/bid/13185
http://www.securityfocus.com/bid/13186
https://exchange.xforce.ibmcloud.com/vulnerabilities/20096