CVE Vulnerabilities

CVE-2005-3745

Published: Nov 22, 2005 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

Affected Software

Name Vendor Start Version End Version
Struts Apache 1.2.7 (including) 1.2.7 (including)
Libstruts1.2-java Ubuntu dapper *
Libstruts1.2-java Ubuntu devel *
Libstruts1.2-java Ubuntu edgy *
Libstruts1.2-java Ubuntu feisty *
Red Hat Application Server 3AS RedHat *
Red Hat Application Server v2 4AS RedHat *

References