CVE-2005-2488

Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:web_content_management:web_content_management_news_system:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:59

Type Values Removed Values Added
References () http://secunia.com/advisories/16317 - Vendor Advisory () http://secunia.com/advisories/16317 - Vendor Advisory
References () http://securitytracker.com/id?1014616 - Exploit () http://securitytracker.com/id?1014616 - Exploit
References () http://www.rgod.altervista.org/webc.html - Exploit () http://www.rgod.altervista.org/webc.html - Exploit
References () http://www.securityfocus.com/bid/14464 - () http://www.securityfocus.com/bid/14464 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/21689 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/21689 -

Information

Published : 2005-08-07 04:00

Updated : 2024-11-20 23:59


NVD link : CVE-2005-2488

Mitre link : CVE-2005-2488

CVE.ORG link : CVE-2005-2488


JSON object : View

Products Affected

web_content_management

  • web_content_management_news_system