4.3

CVE-2005-3955

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BlogbuddiesBlogbuddies Version0.3
JawsJaws Version0.6.2
MagpierssMagpierss Version7.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.58% 0.919
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://secunia.com/advisories/17741
Patch
Vendor Advisory
http://securitytracker.com/id?1015264
http://sourceforge.net/tracker/index.php?func=detail&aid=1366743&group_id=127552&atid=708847
Patch
http://www.securityfocus.com/bid/15555
Exploit
http://retrogod.altervista.org/JAWS_062_sql.html
http://seclists.org/fulldisclosure/2015/May/35
http://secunia.com/advisories/20842
Vendor Advisory
http://www.jaws-project.com/index.php?blog/show/29
http://www.osvdb.org/21112
http://www.osvdb.org/21113
http://www.osvdb.org/21643
http://www.securityfocus.com/archive/1/438434/100/0/threaded
http://www.securityfocus.com/bid/18665
http://www.vupen.com/english/advisories/2006/2546
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/27337