CVE-2005-3047: XSS
Published Sep 23, 2005
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMFCONF[version] parameter to footer.php or (2) PMFLANG[metaLanguage] to header.php.
Affected Software
1 affected component
PhpMyFaq phpmyfaq=1.5.1
Event History
Sep 23, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3047?
The severity of CVE-2005-3047 is considered high due to the potential for remote code execution through cross-site scripting (XSS).
2
What are the components affected by CVE-2005-3047?
CVE-2005-3047 affects the PhpMyFaq version 1.5.1 software, specifically footer.php and header.php files.
3
Who can exploit CVE-2005-3047?
Any remote attacker can exploit CVE-2005-3047 by injecting malicious scripts through the vulnerable parameters.
4
What do the XSS vulnerabilities in CVE-2005-3047 allow attackers to do?
The XSS vulnerabilities in CVE-2005-3047 allow attackers to inject arbitrary web scripts or HTML, potentially compromising user data.