CVE-2005-2338

Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) modules that use "XOOPS Code" and (2) newbb in the forum module.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xoops:xoops:*:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:*:*:*:*:*:*:*:*
cpe:2.3:a:xoops:xoops:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:59

Type Values Removed Values Added
References () http://jvn.jp/jp/JVN%2377105349/index.html - () http://jvn.jp/jp/JVN%2377105349/index.html -
References () http://marc.info/?l=bugtraq&m=113027315412024&w=2 - () http://marc.info/?l=bugtraq&m=113027315412024&w=2 -
References () http://secunia.com/advisories/17300 - Patch, Vendor Advisory () http://secunia.com/advisories/17300 - Patch, Vendor Advisory
References () http://www.kb.cert.org/vuls/id/346302 - US Government Resource () http://www.kb.cert.org/vuls/id/346302 - US Government Resource
References () http://www.kb.cert.org/vuls/id/683958 - US Government Resource () http://www.kb.cert.org/vuls/id/683958 - US Government Resource
References () http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/85_e.html - Patch, Vendor Advisory () http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/85_e.html - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/15195 - () http://www.securityfocus.com/bid/15195 -

Information

Published : 2005-10-27 01:02

Updated : 2024-11-20 23:59


NVD link : CVE-2005-2338

Mitre link : CVE-2005-2338

CVE.ORG link : CVE-2005-2338


JSON object : View

Products Affected

xoops

  • xoops