CVE-2005-1140: XSS
Published Apr 15, 2005
·Updated
Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the comments.
Affected Software
1 affected component
myWebland myBloggie=2.1.1
Event History
Apr 15, 2005
CVE Published
04:00 AM
Apr 16, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1140?
CVE-2005-1140 is classified as a medium severity vulnerability due to its potential for allowing cross-site scripting attacks.
2
How do I fix CVE-2005-1140?
To fix CVE-2005-1140, upgrade myBloggie to the latest version that addresses this vulnerability.
3
What type of attacks can be conducted due to CVE-2005-1140?
CVE-2005-1140 allows remote attackers to conduct cross-site scripting attacks by injecting arbitrary web scripts into comments.
4
Which version of myBloggie is affected by CVE-2005-1140?
CVE-2005-1140 specifically affects myBloggie version 2.1.1.
5
What can attackers do if they exploit CVE-2005-1140?
If exploited, attackers can manipulate user sessions, steal cookies, or perform actions on behalf of users.