Vulnerabilities > CVE-2005-4698 - Cross-Site Scripting vulnerability in Tellme 1.2

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
tellme
exploit available

Summary

Cross-site scripting (XSS) vulnerability in TellMe 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the 91) q_IP (IP) or (2) q_Host (HOST) parameters.

Vulnerable Configurations

Part Description Count
Application
Tellme
1

Exploit-Db

descriptionTellMe 1.2 Multiple Cross-Site Scripting Vulnerabilities. CVE-2005-4698. Webapps exploit for php platform
idEDB-ID:26324
last seen2016-02-03
modified2005-10-05
published2005-10-05
reporterDonnie Werner
sourcehttps://www.exploit-db.com/download/26324/
titleTellMe 1.2 - Multiple Cross-Site Scripting Vulnerabilities