4.3
CVSSv2

CVE-2005-2112

Published: 05/07/2005 Updated: 18/10/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php.

Vulnerable Product Search on Vulmon Subscribe to Product

xoops xoops 2.0

xoops xoops 2.0.5.1

xoops xoops 2.0.5.2

xoops xoops 2.0.11

xoops xoops 2.0.2

xoops xoops 2.0.9

xoops xoops 2.0.9.2

xoops xoops 2.0.3

xoops xoops 2.0.4

xoops xoops 2.0.5

xoops xoops 2.0.9.3

xoops xoops 2.0.1

xoops xoops 2.0.10

xoops xoops 2.0.6

xoops xoops 2.0.7

Exploits

XOOPS Multiple Vulnerabilities Vendor: XOOPS Product: XOOPS Version: <= 2011 Website: wwwxoopsorg/ BID: 14094 14096 CVE: CVE-2005-2112 CVE-2005-2113 OSVDB: 17633 17634 17635 SECUNIA: 15843 PACKETSTORM: 38372 Description: XOOPS is a very popular dynamic web content management system written in Object Oriented PHP One of the fe ...