Lucene search

K
cve[email protected]CVE-2005-2950
HistorySep 16, 2005 - 10:03 p.m.

CVE-2005-2950

2005-09-1622:03:00
web.nvd.nist.gov
29
sawmill
cross-site scripting
xss
vulnerability
web security
http get

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.7 Medium

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.2%

Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through 7.1.13 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP GET request.

Affected configurations

NVD
Node
sawmillsawmillMatch7.0.0
OR
sawmillsawmillMatch7.0.1
OR
sawmillsawmillMatch7.0.2
OR
sawmillsawmillMatch7.0.3
OR
sawmillsawmillMatch7.0.4
OR
sawmillsawmillMatch7.0.5
OR
sawmillsawmillMatch7.0.6
OR
sawmillsawmillMatch7.0.7
OR
sawmillsawmillMatch7.0.8
OR
sawmillsawmillMatch7.0.9
OR
sawmillsawmillMatch7.0.10
OR
sawmillsawmillMatch7.0.10a
OR
sawmillsawmillMatch7.0.10b
OR
sawmillsawmillMatch7.0.10c
OR
sawmillsawmillMatch7.0.10d
OR
sawmillsawmillMatch7.0.10e
OR
sawmillsawmillMatch7.0.10f
OR
sawmillsawmillMatch7.0.10g
OR
sawmillsawmillMatch7.0.10h
OR
sawmillsawmillMatch7.0.10i
OR
sawmillsawmillMatch7.0.10j
OR
sawmillsawmillMatch7.0.10k
OR
sawmillsawmillMatch7.1
OR
sawmillsawmillMatch7.1.1
OR
sawmillsawmillMatch7.1.2
OR
sawmillsawmillMatch7.1.3
OR
sawmillsawmillMatch7.1.4
OR
sawmillsawmillMatch7.1.5
OR
sawmillsawmillMatch7.1.6
OR
sawmillsawmillMatch7.1.7
OR
sawmillsawmillMatch7.1.8
OR
sawmillsawmillMatch7.1.9
OR
sawmillsawmillMatch7.1.10
OR
sawmillsawmillMatch7.1.11
OR
sawmillsawmillMatch7.1.12
OR
sawmillsawmillMatch7.1.13
OR
sawmillsawmillMatch7.1.14

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.7 Medium

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.2%

Related for CVE-2005-2950