CVE-2005-2397: XSS
Published Jul 27, 2005
·Updated
Cross-site scripting (XSS) vulnerability in guestbook.php in phpBook 1.46 allows remote attackers to inject arbitrary web script or HTML via the admin parameter.
Affected Software
1 affected component
GNU Phpbook=1.46
Event History
Jul 27, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2397?
CVE-2005-2397 has a medium severity rating due to its potential for cross-site scripting exploitation.
2
How do I fix CVE-2005-2397?
To mitigate CVE-2005-2397, ensure that input validation and output encoding are implemented properly in the phpBook guestbook.php script.
3
What software versions are affected by CVE-2005-2397?
CVE-2005-2397 affects phpBook version 1.46.
4
What type of vulnerability is CVE-2005-2397?
CVE-2005-2397 is classified as a cross-site scripting (XSS) vulnerability.
5
Who can exploit CVE-2005-2397?
Remote attackers can exploit CVE-2005-2397 to inject arbitrary web scripts or HTML.