First published: Wed Sep 07 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in MAXdev MD-Pro 1.0.72 allow remote attackers to inject arbitrary web script or HTML via (1) dl-search.php or (2) wl-search.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MD-Pro | =1.0.72 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2839 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2005-2839, update MAXdev MD-Pro to a patched version that addresses the XSS vulnerabilities.
The potential impacts of CVE-2005-2839 include unauthorized access to sensitive user data and the ability to execute malicious scripts in the context of the user's session.
CVE-2005-2839 affects MAXdev MD-Pro version 1.0.72.
The attack vectors for CVE-2005-2839 involve injecting scripts through the dl-search.php and wl-search.php files.