Vulnerabilities > CVE-2005-3520 - Cross-Site Scripting vulnerability in MySource

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
mysource
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web script or HTML via (1) the target_url parameter in upgrade_in_progress_backend.php, (2) the stylesheet parameter in edit_table_cell_type_wysiwyg.php, and the bgcolor parameter in (3) insert_table.php, (4) edit_table_cell_props.php, (5) header.php, (6) edit_table_row_props.php, and (7) edit_table_props.php.

Vulnerable Configurations

Part Description Count
Application
Mysource
2

Exploit-Db

  • descriptionMySource 2.14 edit_table_props.php bgcolor Parameter XSS. CVE-2005-3520. Webapps exploit for php platform
    idEDB-ID:26360
    last seen2016-02-03
    modified2005-10-18
    published2005-10-18
    reporterSecunia Research
    sourcehttps://www.exploit-db.com/download/26360/
    titleMySource 2.14 edit_table_props.php bgcolor Parameter XSS
  • descriptionMySource 2.14 header.php bgcolor Parameter XSS. CVE-2005-3520 . Webapps exploit for php platform
    idEDB-ID:26358
    last seen2016-02-03
    modified2005-10-18
    published2005-10-18
    reporterSecunia Research
    sourcehttps://www.exploit-db.com/download/26358/
    titleMySource 2.14 header.php bgcolor Parameter XSS
  • descriptionMySource 2.14 edit_table_row_props.php bgcolor Parameter XSS. CVE-2005-3520 . Webapps exploit for php platform
    idEDB-ID:26359
    last seen2016-02-03
    modified2005-10-18
    published2005-10-18
    reporterSecunia Research
    sourcehttps://www.exploit-db.com/download/26359/
    titleMySource 2.14 edit_table_row_props.php bgcolor Parameter XSS
  • descriptionMySource 2.14 edit_table_cell_props.php bgcolor Parameter XSS. CVE-2005-3520. Webapps exploit for php platform
    idEDB-ID:26357
    last seen2016-02-03
    modified2005-10-18
    published2005-10-18
    reporterSecunia Research
    sourcehttps://www.exploit-db.com/download/26357/
    titleMySource 2.14 edit_table_cell_props.php bgcolor Parameter XSS
  • descriptionMySource 2.14 insert_table.php bgcolor Parameter XSS. CVE-2005-3520. Webapps exploit for php platform
    idEDB-ID:26356
    last seen2016-02-03
    modified2005-10-18
    published2005-10-18
    reporterSecunia Research
    sourcehttps://www.exploit-db.com/download/26356/
    titleMySource 2.14 insert_table.php bgcolor Parameter XSS
  • descriptionMySource 2.14 edit_table_cell_type_wysiwyg.php stylesheet Parameter XSS. CVE-2005-3520. Webapps exploit for php platform
    idEDB-ID:26361
    last seen2016-02-03
    modified2005-10-18
    published2005-10-18
    reporterSecunia Research
    sourcehttps://www.exploit-db.com/download/26361/
    titleMySource 2.14 edit_table_cell_type_wysiwyg.php stylesheet Parameter XSS