CVE-2005-4277
Published Dec 16, 2005
Last updated 6 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in index.php in toendaCMS before 0.7 Beta allows remote attackers to inject arbitrary web script or HTML via the id parameter.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:toenda_software_development:toendacms:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1F1F20EB-C738-4514-92AC-839A6F077515", "versionEndIncluding": "0.6" }, { "criteria": "cpe:2.3:a:toenda_software_development:toendacms:0.6_beta_1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "279254C3-7424-460A-A220-B983ABA0FC63" }, { "criteria": "cpe:2.3:a:toenda_software_development:toendacms:0.6_beta_2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F4C0A93D-4B2C-4E52-B7F7-3AD5E069D0BA" }, { "criteria": "cpe:2.3:a:toenda_software_development:toendacms:0.6_beta_3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "57D3ECDC-D2D1-479E-BC92-1479EB09683D" }, { "criteria": "cpe:2.3:a:toenda_software_development:toendacms:0.6_pre-beta:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B1E4D8C-6B92-4F94-BA51-4D058D2E0F73" } ], "operator": "OR" } ] } ]