CVE-2005-4599: XSS
Published Dec 31, 2005
·Updated
Cross-site scripting (XSS) vulnerability in tinymcegzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to inject arbitrary web script or HTML via the index parameter.
Affected Software
1 affected component
Moxiecode Tinymce Compressor Php<=1.05
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2005
CVE Published
05:00 AM
Jan 2, 2006
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4599?
CVE-2005-4599 is classified as a moderate severity cross-site scripting vulnerability.
2
How do I fix CVE-2005-4599?
To fix CVE-2005-4599, upgrade TinyMCE Compressor PHP to version 1.06 or later.
3
What software versions are affected by CVE-2005-4599?
CVE-2005-4599 affects TinyMCE Compressor PHP versions prior to 1.06, specifically versions up to 1.05.
4
What kind of attack can be performed using CVE-2005-4599?
An attacker can exploit CVE-2005-4599 to inject arbitrary web scripts or HTML into a vulnerable application.
5
Is user input related to the index parameter vulnerable in CVE-2005-4599?
Yes, the index parameter in tiny_mce_gzip.php is specifically vulnerable to cross-site scripting attacks in CVE-2005-4599.