Vulnerabilities > CVE-2005-4277 - Cross-Site Scripting vulnerability in ToendaCMS
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE network
toenda-software-development
Summary
Cross-site scripting (XSS) vulnerability in index.php in toendaCMS before 0.7 Beta allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
References
- http://secunia.com/advisories/18058
- http://securitytracker.com/id?1015354
- http://www.osvdb.org/21767
- http://www.securityfocus.com/archive/1/435412/100/0/threaded
- http://www.securityfocus.com/bid/18178
- http://www.toenda.com/files/toendaCMS_0.7_Beta.zip
- http://www.vupen.com/english/advisories/2005/2926