CVE-2005-0085

Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.
References
Link Resource
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.46/SCOSA-2005.46.txt
http://secunia.com/advisories/14255
http://secunia.com/advisories/14276
http://secunia.com/advisories/14303
http://secunia.com/advisories/14795
http://secunia.com/advisories/15007
http://secunia.com/advisories/17414
http://secunia.com/advisories/17415
http://securitytracker.com/id?1013078
http://www.debian.org/security/2005/dsa-680 Patch Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200502-16.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2005:063
http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00002.html
http://www.redhat.com/support/errata/RHSA-2005-073.html
http://www.redhat.com/support/errata/RHSA-2005-090.html
http://www.securityfocus.com/bid/12442 Patch Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/19223
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10878
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.46/SCOSA-2005.46.txt
http://secunia.com/advisories/14255
http://secunia.com/advisories/14276
http://secunia.com/advisories/14303
http://secunia.com/advisories/14795
http://secunia.com/advisories/15007
http://secunia.com/advisories/17414
http://secunia.com/advisories/17415
http://securitytracker.com/id?1013078
http://www.debian.org/security/2005/dsa-680 Patch Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200502-16.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2005:063
http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00002.html
http://www.redhat.com/support/errata/RHSA-2005-073.html
http://www.redhat.com/support/errata/RHSA-2005-090.html
http://www.securityfocus.com/bid/12442 Patch Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/19223
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10878
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:htdig:htdig:3.1.5:*:*:*:*:*:*:*
cpe:2.3:a:htdig:htdig:3.1.5_7:*:*:*:*:*:*:*
cpe:2.3:a:htdig:htdig:3.1.5_8:*:*:*:*:*:*:*
cpe:2.3:a:htdig:htdig:3.1.6:*:*:*:*:*:*:*
cpe:2.3:a:htdig:htdig:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:htdig:htdig:3.2.0b2:*:*:*:*:*:*:*
cpe:2.3:a:htdig:htdig:3.2.0b3:*:*:*:*:*:*:*
cpe:2.3:a:htdig:htdig:3.2.0b4:*:*:*:*:*:*:*
cpe:2.3:a:htdig:htdig:3.2.0b5:*:*:*:*:*:*:*
cpe:2.3:a:htdig:htdig:3.2.0b6:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:mandrakesoft:mandrake_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux:10.0:*:amd64:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux:10.1:*:*:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux:10.1:*:x86_64:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:*:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:x86_64:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:x86_64:*:*:*:*:*
cpe:2.3:o:redhat:fedora_core:core_3.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:8.0:*:i386:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:8.1:*:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:8.2:*:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.0:*:x86_64:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.1:*:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.2:*:*:*:*:*:*:*

History

20 Nov 2024, 23:54

Type Values Removed Values Added
References () ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.46/SCOSA-2005.46.txt - () ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.46/SCOSA-2005.46.txt -
References () http://secunia.com/advisories/14255 - () http://secunia.com/advisories/14255 -
References () http://secunia.com/advisories/14276 - () http://secunia.com/advisories/14276 -
References () http://secunia.com/advisories/14303 - () http://secunia.com/advisories/14303 -
References () http://secunia.com/advisories/14795 - () http://secunia.com/advisories/14795 -
References () http://secunia.com/advisories/15007 - () http://secunia.com/advisories/15007 -
References () http://secunia.com/advisories/17414 - () http://secunia.com/advisories/17414 -
References () http://secunia.com/advisories/17415 - () http://secunia.com/advisories/17415 -
References () http://securitytracker.com/id?1013078 - () http://securitytracker.com/id?1013078 -
References () http://www.debian.org/security/2005/dsa-680 - Patch, Vendor Advisory () http://www.debian.org/security/2005/dsa-680 - Patch, Vendor Advisory
References () http://www.gentoo.org/security/en/glsa/glsa-200502-16.xml - () http://www.gentoo.org/security/en/glsa/glsa-200502-16.xml -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2005:063 - () http://www.mandriva.com/security/advisories?name=MDKSA-2005:063 -
References () http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00002.html - () http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00002.html -
References () http://www.redhat.com/support/errata/RHSA-2005-073.html - () http://www.redhat.com/support/errata/RHSA-2005-073.html -
References () http://www.redhat.com/support/errata/RHSA-2005-090.html - () http://www.redhat.com/support/errata/RHSA-2005-090.html -
References () http://www.securityfocus.com/bid/12442 - Patch, Vendor Advisory () http://www.securityfocus.com/bid/12442 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/19223 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/19223 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10878 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10878 -

Information

Published : 2005-04-27 04:00

Updated : 2024-11-20 23:54


NVD link : CVE-2005-0085

Mitre link : CVE-2005-0085

CVE.ORG link : CVE-2005-0085


JSON object : View

Products Affected

htdig

  • htdig

suse

  • suse_linux

redhat

  • fedora_core

mandrakesoft

  • mandrake_linux
  • mandrake_linux_corporate_server