Vulnerability CVE-2005-4858


Published: 2005-12-31   Modified: 2012-02-12

Description:
Multiple cross-site scripting (XSS) vulnerabilities in mimic2.cgi in mimicboard2 (Mimic2) 086 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters associated with the (1) name, (2) title, and (3) comment sections, as demonstrated by referencing a remote document through the SRC attribute of an IFRAME element.

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Chitta -> Mimicboard 2 

 References:
http://www.securityfocus.com/bid/14778
http://exploitlabs.com/files/advisories/EXPL-A-2005-013-mimic2.txt

Copyright 2024, cxsecurity.com

 

Back to Top