First published: Tue Nov 22 2005(Updated: )
Cross-site scripting (XSS) vulnerability in Exponent CMS 0.96.3 and later versions allows remote attackers to inject arbitrary web script or HTML via (1) Javascript in forms produced by the form generator or (2) the parameters to the installer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exponent Exponent | =0.94 | |
Exponent Exponent | =0.96.3 | |
Exponent Exponent | =0.96.1 | |
Exponent Exponent | =0.95 | |
Exponent Exponent | =0.96.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3761 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2005-3761, upgrade to a version of Exponent CMS that is not vulnerable, such as any version after 0.96.4.
CVE-2005-3761 affects Exponent CMS versions 0.94, 0.95, 0.96.1, and 0.96.3.
With CVE-2005-3761, remote attackers can inject arbitrary web scripts or HTML into webpages.
CVE-2005-3761 affects the form generator and the parameters to the installer of Exponent CMS.