CVE Vulnerabilities

CVE-2005-3745

Published: Nov 22, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

Affected Software

NameVendorStart VersionEnd Version
StrutsApache1.2.7 (including)1.2.7 (including)
Red Hat Application Server 3ASRedHat*
Red Hat Application Server v2 4ASRedHat*
Libstruts1.2-javaUbuntudapper*
Libstruts1.2-javaUbuntudevel*
Libstruts1.2-javaUbuntuedgy*
Libstruts1.2-javaUbuntufeisty*

References