4.3
CVSSv2

CVE-2005-4167

Published: 11/12/2005 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in eFiction 1.0 and 1.1 allows remote malicious users to inject arbitrary web script or HTML via the let parameter in a viewlist action to titles.php.

Vulnerable Product Search on Vulmon Subscribe to Product

efiction project efiction 1.1

efiction project efiction 1.0

Exploits

source: wwwsecurityfocuscom/bid/15568/info eFiction is prone to SQL injection, remote file upload, and cross site scripting vulnerabilities These vulnerabilities may allow an attacker to view and modify sensitive information, gain unauthorized access, modify and corrupt the underlying database application, and obtain a victim's authenti ...