CVE Vulnerabilities

CVE-2005-3745

Published: Nov 22, 2005 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

Affected Software

Name Vendor Start Version End Version
Struts Apache 1.2.7 (including) 1.2.7 (including)
Red Hat Application Server 3AS RedHat *
Red Hat Application Server v2 4AS RedHat *
Libstruts1.2-java Ubuntu dapper *
Libstruts1.2-java Ubuntu devel *
Libstruts1.2-java Ubuntu edgy *
Libstruts1.2-java Ubuntu feisty *

References