CVE-2005-0458: XSS
Published Feb 17, 2005
·Updated
Cross-site scripting (XSS) vulnerability in contactus.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter.
Affected Software
1 affected component
osCommerce oscommerce=2.2_ms2
Event History
Feb 17, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0458?
CVE-2005-0458 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2005-0458?
To fix CVE-2005-0458, you should sanitize the input to the enquiry parameter in contact_us.php to prevent script injection.
3
Which versions of osCommerce are affected by CVE-2005-0458?
CVE-2005-0458 affects osCommerce version 2.2-MS2.
4
What types of attacks can exploit CVE-2005-0458?
CVE-2005-0458 can be exploited to perform cross-site scripting attacks, allowing attackers to inject arbitrary web scripts or HTML.
5
Is CVE-2005-0458 a known issue in other osCommerce versions?
CVE-2005-0458 specifically affects osCommerce 2.2-MS2, and its impact on other versions has not been detailed in this context.