4.3

CVE-2005-2416

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Astalavista It EngineeringContrexx Version <= 1.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.8% 0.757
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=112206702015439&w=2
http://secunia.com/advisories/16169
http://securitytracker.com/id?1014554
http://www.hardened-php.net/advisory_112005.59.html
Patch
Vendor Advisory
Exploit
http://www.securityfocus.com/bid/14352
http://www.osvdb.org/18168
http://www.osvdb.org/18169
https://exchange.xforce.ibmcloud.com/vulnerabilities/21484
https://exchange.xforce.ibmcloud.com/vulnerabilities/21487