CVE-2005-4494: XSS
Published Dec 22, 2005
·Updated
Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) spiplogin.php3 and (2) spippass.php3.
Affected Software
1 affected component
Spip SPIP=1.8.2
Event History
Dec 22, 2005
CVE Published
11:03 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4494?
CVE-2005-4494 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2005-4494?
To fix CVE-2005-4494, upgrade to SPIP version 1.8.3 or later that addresses this vulnerability.
3
What are the affected versions in CVE-2005-4494?
CVE-2005-4494 affects SPIP versions 1.8.2 and earlier.
4
What types of attacks can be executed via CVE-2005-4494?
CVE-2005-4494 allows remote attackers to execute arbitrary web script or HTML through cross-site scripting.
5
Which files are vulnerable in CVE-2005-4494?
The vulnerable files in CVE-2005-4494 are spip_login.php3 and spip_pass.php3.