4.3

CVE-2005-2338

Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) modules that use "XOOPS Code" and (2) newbb in the forum module.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
XoopsXoops Version <= 2.0.12_jp
XoopsXoops Version <= 2.0.13.1
XoopsXoops Version <= 2.2.3_rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.63% 0.731
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://jvn.jp/jp/JVN%2377105349/index.html
http://marc.info/?l=bugtraq&m=113027315412024&w=2
http://secunia.com/advisories/17300
Patch
Vendor Advisory
http://www.kb.cert.org/vuls/id/346302
US Government Resource
http://www.kb.cert.org/vuls/id/683958
US Government Resource
http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/85_e.html
Patch
Vendor Advisory
http://www.securityfocus.com/bid/15195