CVE-2005-3695: XSS
Published Nov 20, 2005
·Updated
Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the m parameter.
Affected Software
1 affected component
Litespeed Technologies Litespeed Web Server=2.1.5
Event History
Nov 20, 2005
CVE Published
10:03 PM
Nov 21, 2005
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3695?
CVE-2005-3695 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2005-3695?
To fix CVE-2005-3695, upgrade to a version of LiteSpeed Web Server released after 2.1.5 that addresses this cross-site scripting vulnerability.
3
What specific component is affected by CVE-2005-3695?
CVE-2005-3695 affects the 'admin/config/confMgr.php' component of LiteSpeed Web Server 2.1.5.
4
Who is affected by CVE-2005-3695?
Users of LiteSpeed Web Server version 2.1.5 are at risk from the CVE-2005-3695 vulnerability.
5
What type of attack is possible with CVE-2005-3695?
CVE-2005-3695 allows remote attackers to execute arbitrary web script or HTML through cross-site scripting.