First published: Fri Sep 23 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyFAQ | =1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-3047 is considered high due to the potential for remote code execution through cross-site scripting (XSS).
CVE-2005-3047 affects the PhpMyFaq version 1.5.1 software, specifically footer.php and header.php files.
Any remote attacker can exploit CVE-2005-3047 by injecting malicious scripts through the vulnerable parameters.
The XSS vulnerabilities in CVE-2005-3047 allow attackers to inject arbitrary web scripts or HTML, potentially compromising user data.