4.3

CVE-2005-3734

Exploit
Cross-site scripting (XSS) vulnerability in the "add content" page in phpMyFAQ 1.5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) thema, (2) username, and (3) usermail parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phpmyfaq ≫ Phpmyfaq Version 1.5
Phpmyfaq ≫ Phpmyfaq Version 1.5.1
Phpmyfaq ≫ Phpmyfaq Version 1.5.3
Phpmyfaq ≫ Phpmyfaq Version 1.5_alpha1
Phpmyfaq ≫ Phpmyfaq Version 1.5_alpha2
Phpmyfaq ≫ Phpmyfaq Version 1.5_beta1
Phpmyfaq ≫ Phpmyfaq Version 1.5_beta2
Phpmyfaq ≫ Phpmyfaq Version 1.5_beta3
Phpmyfaq ≫ Phpmyfaq Version 1.5_rc1
Phpmyfaq ≫ Phpmyfaq Version 1.5_rc2
Phpmyfaq ≫ Phpmyfaq Version 1.5_rc3
Phpmyfaq ≫ Phpmyfaq Version 1.5_rc4
Phpmyfaq ≫ Phpmyfaq Version 1.5_rc5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.48% 0.705
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/17649
Patch
Vendor Advisory
http://securityreason.com/securityalert/196
http://www.osvdb.org/20989
http://www.phpmyfaq.de/advisory_2005-11-18.php
Vendor Advisory
http://www.securityfocus.com/archive/1/417219/30/0/threaded
http://www.securityfocus.com/bid/15504
Patch
http://www.trapkit.de/advisories/TKADV2005-11-004.txt
Exploit
http://www.vupen.com/english/advisories/2005/2505