4.3
CVSSv2

CVE-2005-0629

Published: 01/03/2005 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) user or (2) Avatar parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

427bb fourtwosevenbb 2.2

427bb fourtwosevenbb 2.2.1

427bb fourtwosevenbb 2.0

427bb fourtwosevenbb 2.0.1

427bb fourtwosevenbb 2.1

427bb fourtwosevenbb 2.1.1

427bb fourtwosevenbb 2.1.2

427bb fourtwosevenbb 2.1.3

Exploits

source: wwwsecurityfocuscom/bid/12693/info 427BB is reportedly affected by multiple remote HTML injection vulnerabilities These issues occur because the application fails to properly sanitize user-supplied input before using it in dynamically generated content The attacker-supplied HTML and script code would be able to access propertie ...