Vulnerabilities > CVE-2005-4546 - Cross-Site Scripting vulnerability in Epic Designs Eggblog Search.PHP

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
epic-designs

Summary

search.php in eggblog 2.0 allows remote attackers to obtain the full path via an invalid q parameter, as used by the Keyword and Search fields, possibly due to an SQL injection vulnerability.

Vulnerable Configurations

Part Description Count
Application
Epic_Designs
1