Vulnerabilities > CVE-2005-2488 - Unspecified vulnerability in web Content Management web Content Management News System
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN web-content-management
exploit available
Summary
Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Web Content Management List.php strTable Parameter XSS. CVE-2005-2488. Webapps exploit for php platform |
id | EDB-ID:26068 |
last seen | 2016-02-03 |
modified | 2005-08-03 |
published | 2005-08-03 |
reporter | rgod |
source | https://www.exploit-db.com/download/26068/ |
title | Web Content Management List.php strTable Parameter XSS |
References
- http://secunia.com/advisories/16317
- http://secunia.com/advisories/16317
- http://securitytracker.com/id?1014616
- http://securitytracker.com/id?1014616
- http://www.rgod.altervista.org/webc.html
- http://www.rgod.altervista.org/webc.html
- http://www.securityfocus.com/bid/14464
- http://www.securityfocus.com/bid/14464
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21689
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21689