First published: Tue Dec 20 2005(Updated: )
Cross-site scripting (XSS) vulnerability in admin/Default.asp in iCMS allows remote attackers to inject arbitrary web script or HTML via the LoginMSG parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iCMS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4396 has a high severity due to its potential for remote code execution through cross-site scripting.
To fix CVE-2005-4396, validate and sanitize user inputs for the LoginMSG parameter to prevent script injection.
CVE-2005-4396 affects iCMS content management systems that use the Default.asp script in the admin directory.
Yes, CVE-2005-4396 can be easily exploited by attackers to inject arbitrary web scripts or HTML.
The impact of CVE-2005-4396 can lead to data theft, session hijacking, and defacement of the affected web application.