Vulnerabilities > CVE-2005-1012 - Cross-Site Scripting vulnerability in SiteEnable

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
iatek
nessus

Summary

Cross-site scripting (XSS) vulnerability in Iatek SiteEnable allows remote attackers to inject arbitrary web script or HTML via (1) the contenttype parameter to content.asp, (2) the title, or (3) the description.

Vulnerable Configurations

Part Description Count
Application
Iatek
1

Nessus

NASL familyCGI abuses
NASL idSITEENABLE_SORTBY_SQL_INJECTION.NASL
descriptionThe remote host is running a version of the SiteEnable CMS package that has several vulnerabilities : - SQL Injection Vulnerability Due to a failure to properly sanitize user input to the
last seen2020-06-01
modified2020-06-02
plugin id17970
published2005-04-05
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/17970
titleSiteEnable Multiple Input Validation Vulnerabilities