First published: Sun Aug 21 2005(Updated: )
Cross-site scripting (XSS) vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to inject arbitrary web script or HTML and modify web pages via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xerox Document Centre 420 | ||
Xerox Document Centre 555 | ||
Xerox Document Centre 332 | ||
Xerox Document Centre 535 | ||
Xerox Document Centre 490 | ||
Xerox Document Centre 340 | ||
Xerox Document Centre 265 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-2647 is considered medium due to its potential for cross-site scripting attacks.
To fix CVE-2005-2647, update the affected Xerox Document Centre models to the latest firmware that addresses this vulnerability.
CVE-2005-2647 affects Xerox Document Centre models 220, 265, 332, 340, 420, 490, and 535 to 555.
CVE-2005-2647 can be exploited through cross-site scripting (XSS) attacks allowing attackers to inject arbitrary web scripts or HTML.
Yes, CVE-2005-2647 remains a risk if the affected Xerox Document Centre devices have not been updated or patched.