CVE-2005-2336

Cross-site scripting (XSS) vulnerability in Hiki 0.8.0 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via "missing pages" in which the page name is not properly escaped, a different vulnerability than CVE-2005-2803.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hiki:hiki:0.8.0:*:*:*:*:*:*:*
cpe:2.3:a:hiki:hiki:0.8.1:*:*:*:*:*:*:*
cpe:2.3:a:hiki:hiki:0.8.2:*:*:*:*:*:*:*

History

20 Nov 2024, 23:59

Type Values Removed Values Added
References () http://hikiwiki.org/en/advisory20050804.html - Patch, Vendor Advisory () http://hikiwiki.org/en/advisory20050804.html - Patch, Vendor Advisory
References () http://jvn.jp/en/jp/JVN38138980/index.html - () http://jvn.jp/en/jp/JVN38138980/index.html -
References () http://secunia.com/advisories/17075 - () http://secunia.com/advisories/17075 -
References () http://www.securityfocus.com/bid/15021 - () http://www.securityfocus.com/bid/15021 -

Information

Published : 2005-09-06 21:03

Updated : 2024-11-20 23:59


NVD link : CVE-2005-2336

Mitre link : CVE-2005-2336

CVE.ORG link : CVE-2005-2336


JSON object : View

Products Affected

hiki

  • hiki