4.3
CVE-2005-3204
- EPSS 37.89%
- Published 14.10.2005 10:02:00
- Last modified 03.04.2025 01:03:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request.
Data is provided by the National Vulnerability Database (NVD)
Oracle ≫ Application Server Version9.0.2
Oracle ≫ Application Server Version9.0.2.0.0
Oracle ≫ Application Server Version9.0.2.0.1
Oracle ≫ Application Server Version9.0.2.1
Oracle ≫ Application Server Version9.0.2.2
Oracle ≫ Application Server Version9.0.2.3
Oracle ≫ Application Server Version9.0.3
Oracle ≫ Application Server Version9.0.3.1
Oracle ≫ Application Server Version9.2.0.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 37.89% | 0.969 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|