4.3

CVE-2005-3473

Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4) scheme_name parameter and (5) bg_color parameters (involving the preset_name and result variables) in (c) colors.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Alexander PalmoSimple Php Blog Version0.4.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.18% 0.8
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/17404
http://securityreason.com/securityalert/138
http://www.osvdb.org/20436
http://www.osvdb.org/20437
http://www.osvdb.org/20438
http://www.seclab.tuwien.ac.at/advisories/TUVSA-0511-001.txt
Vendor Advisory
http://www.securityfocus.com/archive/1/415463
http://www.securityfocus.com/bid/15283