4.3
CVE-2005-3334
- EPSS 4.64%
- Veröffentlicht 27.10.2005 10:02:00
- Zuletzt bearbeitet 16.06.2026 22:16:44
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script or HTML via the (1) PHPSESSID, (2) task, (3) string, (4) type, (5) serv, (6) due, (7) dev, and (8) sort2 parameters.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.64% | 0.905 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://flyspray.rocks.cc/bts/task/703
http://lostmon.blogspot.com/2005/10/flyspray-bug-killer-multiple-variable.html
http://secunia.com/advisories/17316
http://secunia.com/advisories/18606
http://www.debian.org/security/2006/dsa-953
http://www.osvdb.org/20326
http://www.securityfocus.com/bid/15209
https://exchange.xforce.ibmcloud.com/vulnerabilities/22889