4.3
CVSSv2

CVE-2005-4454

Published: 21/12/2005 Updated: 20/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote malicious users to conduct cross-site scripting (XSS) attacks via a "\" (backslash) within a "javascript" scheme in a style property (such as "javas\cript"), which bypasses the "javascript" check before the "\" is stripped and then rendered in web browsers that allow scripting in style sheets.

Vulnerable Product Search on Vulmon Subscribe to Product

livejournal livejournal

Exploits

source: wwwsecurityfocuscom/bid/15990/info LiveJournal is prone to an HTML injection vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input before using it in dynamically generated content Attacker-supplied HTML and script code would be executed in the context of the affected Web site, ...