VDB
CVE-2005-0085
CVE-2005-0085
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.
EPSS 2.27% · 81.4th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
2.27%
81.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mandrakesoft | mandrake_linux_corporate_server | 2.1, 2.1, 3.0 |
| mandrakesoft | mandrake_linux | 10.0, 10.1, 10.1 |
| suse | suse_linux | 9.0, 8.0, 8.0 |
| redhat | fedora_core | core_3.0 |
| htdig | htdig | 3.1.5_8, 3.1.5_7, * |
| n/a | n/a | * |
Timeline
- Feb 15, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- RHSA-2005:073 vendor-advisory
- 14255 third-party-advisory
- RHSA-2005:090 vendor-advisory
- FLSA-2006:152907 vendor-advisory
- 15007 third-party-advisory
- SCOSA-2005.46 vendor-advisory
- 14795 third-party-advisory
- MDKSA-2005:063 vendor-advisory
- http://secunia.com/advisories/17414 technical
- http://www.debian.org/security/2005/dsa-680 patch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10878 technical
- http://secunia.com/advisories/14276 technical
- http://secunia.com/advisories/14303 technical
- http://secunia.com/advisories/17415 technical
- http://www.securityfocus.com/bid/12442 patch
- https://nvd.nist.gov/vuln/detail/CVE-2005-0085 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19223 url
- http://securitytracker.com/id?1013078 url
- http://www.gentoo.org/security/en/glsa/glsa-200502-16.xml url