Lucene search

K
cve[email protected]CVE-2009-0285
HistoryJan 27, 2009 - 6:30 p.m.

CVE-2009-0285

2009-01-2718:30:00
CWE-79
web.nvd.nist.gov
20
cve-2009-0285
cross-site scripting
xss
bbsxp 5.13
security vulnerability

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

51.3%

Cross-site scripting (XSS) vulnerability in error.asp in BBSXP 5.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter.

Affected configurations

NVD
Node
bbsxpbbsxpRange5.13
CPENameOperatorVersion
bbsxp:bbsxpbbsxple5.13

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

51.3%

Related for CVE-2009-0285