Lucene search

K
cve[email protected]CVE-2005-3556
HistoryNov 16, 2005 - 7:42 a.m.

CVE-2005-3556

2005-11-1607:42:00
web.nvd.nist.gov
24
cve-2005-3556
cross-site scripting
xss
phplist
security vulnerabilities
remote attack

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6 Medium

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.2%

Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (a) admin/editlist.php, (2) title parameter in (b) admin/spageedit.php, (3) title field in © admin/template.php, (4) filter, (5) delete, and (6) start parameters in (d) admin/eventlog.php, (7) id parameter in (e) admin/configure.php, (8) find parameter in (f) admin/users.php, (9) start parameter in (g) admin/admin.php, and (10) action parameter in (h) admin/fckphplist.php.

Affected configurations

NVD
Node
tincanphplistRange2.10.1
CPENameOperatorVersion
tincan:phplisttincan phplistle2.10.1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6 Medium

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.2%

Related for CVE-2005-3556