Cross-site scripting (XSS) vulnerability in SearchFeed Search Engine 1.3.2 and earlier allows remote attackers to inject arbitrary HTML and web script, possibly via the REQ parameter, which is used when performing a search.
References
Configurations
History
21 Nov 2024, 00:02
Type | Values Removed | Values Added |
---|---|---|
References | () http://pridels0.blogspot.com/2005/11/searchfeed-search-engine-xss-vuln.html - | |
References | () http://secunia.com/advisories/17715 - Vendor Advisory | |
References | () http://www.osvdb.org/21144 - | |
References | () http://www.securityfocus.com/bid/15612 - Exploit | |
References | () http://www.vupen.com/english/advisories/2005/2609 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/23348 - |
Information
Published : 2005-11-29 11:03
Updated : 2024-11-21 00:02
NVD link : CVE-2005-3866
Mitre link : CVE-2005-3866
CVE.ORG link : CVE-2005-3866
JSON object : View
Products Affected
wwwsearchsolutions
- searchfeed_search_engine
CWE