Vulnerabilities > CVE-2005-4307 - Cross-Site Scripting vulnerability in ScareCrow

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
jonathan-bravata
exploit available

Summary

Cross-site scripting (XSS) vulnerability in ScareCrow 2.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter to (1) forum.cgi and (2) post.cgi, or (3) the user parameter to profile.cgi.

Exploit-Db

  • descriptionScareCrow 2.13 profile.cgi user Parameter XSS. CVE-2005-4307. Webapps exploit for cgi platform
    idEDB-ID:26862
    last seen2016-02-03
    modified2005-12-16
    published2005-12-16
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/26862/
    titleScareCrow 2.13 profile.cgi user Parameter XSS
  • descriptionScareCrow 2.13 forum.cgi forum Parameter XSS. CVE-2005-4307. Webapps exploit for cgi platform
    idEDB-ID:26861
    last seen2016-02-03
    modified2005-12-16
    published2005-12-16
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/26861/
    titleScareCrow 2.13 forum.cgi forum Parameter XSS
  • descriptionScareCrow 2.13 post.cgi forum Parameter XSS. CVE-2005-4307. Webapps exploit for cgi platform
    idEDB-ID:26863
    last seen2016-02-03
    modified2005-12-16
    published2005-12-16
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/26863/
    titleScareCrow 2.13 post.cgi forum Parameter XSS