Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to get_jsrs_data.php.
References
Link | Resource |
---|---|
http://lists.mysql.com/eventum-users/2072 | Patch |
http://marc.info/?l=bugtraq&m=112292193807958&w=2 | |
http://secunia.com/advisories/16304 | Patch Vendor Advisory |
http://securitytracker.com/id?1014603 | Exploit Patch |
http://www.gulftech.org/?node=research&article_id=00093-07312005 | Exploit |
http://www.osvdb.org/18400 | Exploit |
http://www.osvdb.org/18401 | Exploit |
http://www.osvdb.org/18402 | Exploit |
http://www.securityfocus.com/bid/14436 | Exploit |
http://www.vupen.com/english/advisories/2005/1287 | |
http://lists.mysql.com/eventum-users/2072 | Patch |
http://marc.info/?l=bugtraq&m=112292193807958&w=2 | |
http://secunia.com/advisories/16304 | Patch Vendor Advisory |
http://securitytracker.com/id?1014603 | Exploit Patch |
http://www.gulftech.org/?node=research&article_id=00093-07312005 | Exploit |
http://www.osvdb.org/18400 | Exploit |
http://www.osvdb.org/18401 | Exploit |
http://www.osvdb.org/18402 | Exploit |
http://www.securityfocus.com/bid/14436 | Exploit |
http://www.vupen.com/english/advisories/2005/1287 |
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.mysql.com/eventum-users/2072 - Patch | |
References | () http://marc.info/?l=bugtraq&m=112292193807958&w=2 - | |
References | () http://secunia.com/advisories/16304 - Patch, Vendor Advisory | |
References | () http://securitytracker.com/id?1014603 - Exploit, Patch | |
References | () http://www.gulftech.org/?node=research&article_id=00093-07312005 - Exploit | |
References | () http://www.osvdb.org/18400 - Exploit | |
References | () http://www.osvdb.org/18401 - Exploit | |
References | () http://www.osvdb.org/18402 - Exploit | |
References | () http://www.securityfocus.com/bid/14436 - Exploit | |
References | () http://www.vupen.com/english/advisories/2005/1287 - |
Information
Published : 2005-12-31 05:00
Updated : 2024-11-20 23:59
NVD link : CVE-2005-2467
Mitre link : CVE-2005-2467
CVE.ORG link : CVE-2005-2467
JSON object : View
Products Affected
mysql
- eventum
CWE