4.3
CVE-2005-3866
- EPSS 1.38%
- Veröffentlicht 29.11.2005 11:03:00
- Zuletzt bearbeitet 16.06.2026 22:17:46
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in SearchFeed Search Engine 1.3.2 and earlier allows remote attackers to inject arbitrary HTML and web script, possibly via the REQ parameter, which is used when performing a search.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wwwsearchsolutions ≫ Searchfeed Search Engine Version <= 1.3.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.38% | 0.686 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://pridels0.blogspot.com/2005/11/searchfeed-search-engine-xss-vuln.html
http://secunia.com/advisories/17715
http://www.osvdb.org/21144
http://www.securityfocus.com/bid/15612
http://www.vupen.com/english/advisories/2005/2609
https://exchange.xforce.ibmcloud.com/vulnerabilities/23348