CVE-2005-3403: XSS
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the basehref parameter in translate.php, (2) the basepath parameter in news.inc.php, and (3) the p parameter in addnote.php.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3403?
CVE-2005-3403 is classified as a medium-severity vulnerability due to its potential impact on web applications.
How do I fix CVE-2005-3403?
To fix CVE-2005-3403, upgrade to ATutor version 1.4.3 or later, where the vulnerabilities have been addressed.
What are the affected versions in CVE-2005-3403?
The affected versions for CVE-2005-3403 include ATutor 1.4.1 to 1.5.1-pl1.
What types of vulnerabilities does CVE-2005-3403 involve?
CVE-2005-3403 involves multiple cross-site scripting (XSS) vulnerabilities.
Can CVE-2005-3403 affect my website?
Yes, if you use an affected version of ATutor, your website may be susceptible to attacks exploiting this vulnerability.