Vulnerabilities > CVE-2005-2488 - Cross-Site Scripting vulnerability in Web Content Management

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
web-content-management
exploit available

Summary

Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.

Vulnerable Configurations

Part Description Count
Application
Web_Content_Management
1

Exploit-Db

descriptionWeb Content Management List.php strTable Parameter XSS. CVE-2005-2488. Webapps exploit for php platform
idEDB-ID:26068
last seen2016-02-03
modified2005-08-03
published2005-08-03
reporterrgod
sourcehttps://www.exploit-db.com/download/26068/
titleWeb Content Management List.php strTable Parameter XSS