Lucene search

K
cveMitreCVE-2005-3688
HistoryNov 19, 2005 - 1:03 a.m.

CVE-2005-3688

2005-11-1901:03:00
mitre
web.nvd.nist.gov
22
cross-site scripting
xss
vulnerability
xmb 1.9.3
remote attackers
injection

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.009

Percentile

83.1%

Cross-site scripting (XSS) vulnerability in members.php in XMB 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the “Your Current Mood” field in the registration page.

Affected configurations

Nvd
Node
xmb_forumxmbRange1.9.3
OR
xmb_forumxmbMatch1.8_sp1
OR
xmb_forumxmbMatch1.8_sp2
OR
xmb_forumxmbMatch1.8_sp3
OR
xmb_forumxmbMatch1.9.1
OR
xmb_forumxmbMatch1.9.2
OR
xmb_forumxmbMatch1.9_beta
VendorProductVersionCPE
xmb_forumxmb*cpe:2.3:a:xmb_forum:xmb:*:*:*:*:*:*:*:*
xmb_forumxmb1.8_sp1cpe:2.3:a:xmb_forum:xmb:1.8_sp1:*:*:*:*:*:*:*
xmb_forumxmb1.8_sp2cpe:2.3:a:xmb_forum:xmb:1.8_sp2:*:*:*:*:*:*:*
xmb_forumxmb1.8_sp3cpe:2.3:a:xmb_forum:xmb:1.8_sp3:*:*:*:*:*:*:*
xmb_forumxmb1.9.1cpe:2.3:a:xmb_forum:xmb:1.9.1:*:*:*:*:*:*:*
xmb_forumxmb1.9.2cpe:2.3:a:xmb_forum:xmb:1.9.2:*:*:*:*:*:*:*
xmb_forumxmb1.9_betacpe:2.3:a:xmb_forum:xmb:1.9_beta:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.009

Percentile

83.1%

Related for CVE-2005-3688