4.3
CVE-2005-2650
- EPSS 1.21%
- Veröffentlicht 23.08.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:15:24
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in sign.asp in Emefa Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, and (3) email parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emefa ≫ Emefa Guestbook Version1.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.21% | 0.644 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://packetstormsecurity.org/0508-advisories/emefaGuest.txt
http://secunia.com/advisories/16489
http://systemsecure.org/ssforum/viewtopic.php?t=91
http://www.emefa.myserver.org/comp/guestview.php
http://www.securityfocus.com/bid/14599