4.3
CVE-2005-4012
- EPSS 1.85%
- Veröffentlicht 05.12.2005 11:03:00
- Zuletzt bearbeitet 16.06.2026 22:18:03
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in PHP Web Statistik 1.4 allows remote attackers to inject arbitrary web script or HTML via (1) the lastnumber parameter to stat.php and (2) the HTTP referer to pixel.php.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.85% | 0.763 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://cert.uni-stuttgart.de/archive/bugtraq/2005/11/msg00325.html
http://freewebstat.com/changelog-english.html
http://secunia.com/advisories/17789
http://www.osvdb.org/21208
http://www.osvdb.org/21212
http://www.securityfocus.com/bid/15603
http://www.ush.it/2005/11/19/php-web-statistik/
http://www.vupen.com/english/advisories/2005/2645
https://exchange.xforce.ibmcloud.com/vulnerabilities/23379
https://exchange.xforce.ibmcloud.com/vulnerabilities/23385