4.3
CVSSv2

CVE-2005-3308

Published: 26/10/2005 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote malicious users to inject arbitrary web script or HTML via the (1) name or (2) comment parameter in detail.php, (3) the username parameter in get.php, and (4) the search parameter in index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

zomplog zomplog 3.3

zomplog zomplog 3.4

Exploits

source: wwwsecurityfocuscom/bid/15168/info Zomplog is prone to an HTML injection vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content Attacker-supplied HTML and script code would be executed in the context of the affected Web site, pote ...