Lucene search

K
cve[email protected]CVE-2005-2057
HistoryJun 29, 2005 - 4:00 a.m.

CVE-2005-2057

2005-06-2904:00:00
web.nvd.nist.gov
25
cve-2005-2057
xss
infopop ubb.threads
security vulnerability
web script injection
html injection
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.007 Low

EPSS

Percentile

79.7%

Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to newreply.php, (5) Number, (6) Board, or (7) what parameter to showprofile.php, (8) fpart or (9) page parameter to showflat.php, or (10) like parameter to showmembers.php.

Affected configurations

NVD
Node
ubbcentralubb.threadsMatch6.0
OR
ubbcentralubb.threadsMatch6.0.1
OR
ubbcentralubb.threadsMatch6.0.2
OR
ubbcentralubb.threadsMatch6.0.3
OR
ubbcentralubb.threadsMatch6.1
OR
ubbcentralubb.threadsMatch6.1.1
OR
ubbcentralubb.threadsMatch6.2
OR
ubbcentralubb.threadsMatch6.2.1
OR
ubbcentralubb.threadsMatch6.2.2
OR
ubbcentralubb.threadsMatch6.2.3
OR
ubbcentralubb.threadsMatch6.3
OR
ubbcentralubb.threadsMatch6.3.1
OR
ubbcentralubb.threadsMatch6.4
OR
ubbcentralubb.threadsMatch6.4.1
OR
ubbcentralubb.threadsMatch6.4.2
OR
ubbcentralubb.threadsMatch6.4.3
OR
ubbcentralubb.threadsMatch6.4.4
OR
ubbcentralubb.threadsMatch6.5
OR
ubbcentralubb.threadsMatch6.5.1
OR
ubbcentralubb.threadsMatch6.5.1.1

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.007 Low

EPSS

Percentile

79.7%

Related for CVE-2005-2057