First published: Thu Dec 22 2005(Updated: )
Cross-site scripting (XSS) vulnerability in OpenCms 6.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alkacon OpenCMS | =6.0.3 | |
Alkacon OpenCMS | =6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4475 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2005-4475, upgrade OpenCms to version 6.0.4 or later, which addresses the XSS vulnerability.
CVE-2005-4475 affects OpenCms versions 6.0.2 and 6.0.3.
CVE-2005-4475 allows attackers to execute arbitrary web scripts or HTML in the context of the user’s session.
CVE-2005-4475 may not be widespread as it affects specific older versions of OpenCms, but it poses risks for users who have not updated.