| |
Vulnerability CVE-2005-4383
Published: 2005-12-19 Modified: 2012-02-12
Description: |
Cross-site scripting (XSS) vulnerability in index.cfm in CitySoft Community Enterprise 4.x allows remote attackers to inject arbitrary web script or HTML via the (1) presentationSite, (2) docPublishYear, (3) docDescription, (4) publishState, (5) docAuthor, (6) docTitle, (7) subTopic, (8) topic, (9) topicRadio, (10) topicOnly, (11) startrow, and (12) sortby parameters. |
CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
4.3/10 |
2.9/10 |
8.6/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Medium |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
None |
Partial |
None |
References: |
http://pridels0.blogspot.com/2005/12/community-enterprise-4x-multiple-vuln.html
http://www.vupen.com/english/advisories/2005/2979
https://exchange.xforce.ibmcloud.com/vulnerabilities/23821
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|