CVE-2005-3425: XSS
Published Nov 1, 2005
·Updated
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2005-3424.
Affected Software
16 affected components
GNU gnump3d=2.0
GNU gnump3d=2.1
GNU gnump3d=2.2
GNU gnump3d=2.3
GNU gnump3d=2.4
GNU gnump3d=2.5
GNU gnump3d=2.5b
GNU gnump3d=2.6
GNU gnump3d=2.7
GNU gnump3d=2.8
GNU gnump3d=2.9
GNU gnump3d=2.9.1
GNU gnump3d=2.9.2
GNU gnump3d=2.9.3
GNU gnump3d=2.9.4
GNU gnump3d=2.9.5
Remediation
Patch Available
Event History
Nov 1, 2005
CVE Published
10:02 PM
Nov 2, 2005
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3425?
CVE-2005-3425 is considered a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2005-3425?
To fix CVE-2005-3425, upgrade GNUMP3D to version 2.9.6 or later, which addresses this vulnerability.
3
Which versions of GNUMP3D are affected by CVE-2005-3425?
CVE-2005-3425 affects GNUMP3D versions prior to 2.9.6, including 2.9.5 and earlier.
4
What types of attacks can be executed due to CVE-2005-3425?
CVE-2005-3425 allows remote attackers to inject arbitrary web script or HTML into a web page.
5
Is CVE-2005-3425 related to any other vulnerabilities?
CVE-2005-3425 is a different vulnerability than CVE-2005-3424, although both impact GNUMP3D.