6.8
CVSSv2

CVE-2004-1075

Published: 10/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in standard_error_message.dtml for Zwiki after 0.10.0rc1 to 0.36.2 allows remote malicious users to inject arbitrary HTML and web script via a malformed URL, which is not properly cleansed when generating an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

zwiki zwiki 0.36.2

zwiki zwiki 0.10_rc1

Exploits

source: wwwsecurityfocuscom/bid/11745/info It is reported that Zwiki is susceptible to a cross-site scripting vulnerability This issue is due to a failure of the application to properly sanitize user-supplied URI input prior to including it in dynamic web page content This issue could permit a remote attacker to create a malicious URI ...