4.3
CVE-2005-3955
- EPSS 5.58%
- Veröffentlicht 01.12.2005 06:03:00
- Zuletzt bearbeitet 16.06.2026 22:17:57
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.58% | 0.919 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
http://secunia.com/advisories/17741
http://securitytracker.com/id?1015264
http://sourceforge.net/tracker/index.php?func=detail&aid=1366743&group_id=127552&atid=708847
http://www.securityfocus.com/bid/15555
http://retrogod.altervista.org/JAWS_062_sql.html
http://seclists.org/fulldisclosure/2015/May/35
http://secunia.com/advisories/20842
http://www.jaws-project.com/index.php?blog/show/29
http://www.osvdb.org/21112
http://www.osvdb.org/21113
http://www.osvdb.org/21643
http://www.securityfocus.com/archive/1/438434/100/0/threaded
http://www.securityfocus.com/bid/18665
http://www.vupen.com/english/advisories/2006/2546
https://exchange.xforce.ibmcloud.com/vulnerabilities/27337