Vulnerabilities > CVE-2005-4727 - Cross-Site Scripting vulnerability in Gbook 1.0/1.0.1

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
martin-bauer

Summary

Cross-site scripting (XSS) vulnerability in gbook.cgi in gBook before 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header field.

Vulnerable Configurations

Part Description Count
Application
Martin_Bauer
2