CVE-2005-2894

medium

Description

Cross-site scripting (XSS) vulnerability in the user registration in PBLang 4.65, and possibly earlier versions, allows remote attackers to inject arbitrary web script or PHP via the location field.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/22190

http://www.securityfocus.com/bid/14766

http://marc.info/?l=bugtraq&m=112611338417979&w=2

Details

Source: Mitre, NVD

Published: 2005-09-14

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium