CVE-2005-0085: XSS
Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0085?
CVE-2005-0085 is classified as a medium severity vulnerability due to its potential for Cross-site scripting (XSS) attacks.
How do I fix CVE-2005-0085?
Fix CVE-2005-0085 by upgrading to ht://dig versions 3.1.6-r7 or later, which include proper sanitization of the config parameter.
What software is affected by CVE-2005-0085?
CVE-2005-0085 affects ht://dig versions prior to 3.1.6-r7, including versions such as 3.1.5 and 3.2.0 beta releases.
What type of attacks can CVE-2005-0085 enable?
CVE-2005-0085 enables remote attackers to execute arbitrary web scripts or HTML through the unsanitized config parameter.
Is there a known exploit for CVE-2005-0085?
Yes, there are known exploits for CVE-2005-0085 that demonstrate how the XSS vulnerability can be exploited.