Lucene search

K
cveMitreCVE-2005-3264
HistoryOct 20, 2005 - 10:02 a.m.

CVE-2005-3264

2005-10-2010:02:00
mitre
web.nvd.nist.gov
23
cve-2005-3264
cross-site scripting
xss
zeroblog
thread.php
web security

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.004

Percentile

72.7%

Cross-site scripting (XSS) vulnerability in thread.php for Zeroblog 1.1f and 1.2a allows remote attackers to inject arbitrary web script or HTML via the threadID parameter.

Affected configurations

Nvd
Node
zeroblogzeroblogMatch1.1f
OR
zeroblogzeroblogMatch1.2a
VendorProductVersionCPE
zeroblogzeroblog1.1fcpe:2.3:a:zeroblog:zeroblog:1.1f:*:*:*:*:*:*:*
zeroblogzeroblog1.2acpe:2.3:a:zeroblog:zeroblog:1.2a:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.004

Percentile

72.7%

Related for CVE-2005-3264