First published: Tue Nov 22 2005(Updated: )
Cross-site scripting (XSS) vulnerability in the "add content" page in phpMyFAQ 1.5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) thema, (2) username, and (3) usermail parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyFAQ | =1.5_rc5 | |
phpMyFAQ | =1.5_rc4 | |
phpMyFAQ | =1.5_alpha1 | |
phpMyFAQ | =1.5_alpha2 | |
phpMyFAQ | =1.5.1 | |
phpMyFAQ | =1.5.3 | |
phpMyFAQ | =1.5_rc2 | |
phpMyFAQ | =1.5_beta2 | |
phpMyFAQ | =1.5_rc3 | |
phpMyFAQ | =1.5_rc1 | |
phpMyFAQ | =1.5_beta1 | |
phpMyFAQ | =1.5 | |
phpMyFAQ | =1.5_beta3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3734 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2005-3734, update phpMyFAQ to version 1.5.4 or later, which addresses this XSS vulnerability.
CVE-2005-3734 affects phpMyFAQ versions 1.5.3 and earlier, including various alpha, beta, and release candidate versions.
Exploiting CVE-2005-3734 can allow an attacker to inject arbitrary web scripts or HTML into the application, compromising user security.
You can identify if your system is vulnerable to CVE-2005-3734 by checking if you are running phpMyFAQ version 1.5.3 or earlier.