4.3

CVE-2005-3902

Exploit
Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as demonstrated using a parameter containing script.
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.19% 0.801
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/039000.html
Patch
Vendor Advisory
http://marc.info/?l=bugtraq&m=113269811630139&w=2
http://moritz-naumann.com/adv/0006/vhcsxss/0006.txt
Patch
Vendor Advisory
http://secunia.com/advisories/17704/
Patch
Vendor Advisory
http://securityreason.com/securityalert/202
http://www.osvdb.org/21060
Exploit
http://www.securityfocus.com/bid/15538
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/23209