Lucene search

K
cve[email protected]CVE-2005-0085
HistoryApr 27, 2005 - 4:00 a.m.

CVE-2005-0085

2005-04-2704:00:00
web.nvd.nist.gov
32
cve
cross-site scripting
xss
ht://dig
vulnerability
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

5.7 Medium

AI Score

Confidence

High

0.023 Low

EPSS

Percentile

89.8%

Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.

Affected configurations

NVD
Node
htdightdigMatch3.1.5
OR
htdightdigMatch3.1.5_7
OR
htdightdigMatch3.1.5_8
OR
htdightdigMatch3.1.6
OR
htdightdigMatch3.2.0
OR
htdightdigMatch3.2.0b2
OR
htdightdigMatch3.2.0b3
OR
htdightdigMatch3.2.0b4
OR
htdightdigMatch3.2.0b5
OR
htdightdigMatch3.2.0b6
Node
mandrakesoftmandrake_linuxMatch10.0
OR
mandrakesoftmandrake_linuxMatch10.0amd64
OR
mandrakesoftmandrake_linuxMatch10.1
OR
mandrakesoftmandrake_linuxMatch10.1x86_64
OR
mandrakesoftmandrake_linux_corporate_serverMatch2.1
OR
mandrakesoftmandrake_linux_corporate_serverMatch2.1x86_64
OR
mandrakesoftmandrake_linux_corporate_serverMatch3.0
OR
mandrakesoftmandrake_linux_corporate_serverMatch3.0x86_64
OR
redhatfedora_coreMatchcore_3.0
OR
susesuse_linuxMatch8.0
OR
susesuse_linuxMatch8.0i386
OR
susesuse_linuxMatch8.1
OR
susesuse_linuxMatch8.2
OR
susesuse_linuxMatch9.0
OR
susesuse_linuxMatch9.0x86_64
OR
susesuse_linuxMatch9.1
OR
susesuse_linuxMatch9.2

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

5.7 Medium

AI Score

Confidence

High

0.023 Low

EPSS

Percentile

89.8%