CVE Vulnerabilities

CVE-2005-4481

Published: Dec 22, 2005 | Modified: Apr 11, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in Polopoly 9 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters. NOTE: the vendor has disputed this vulnerability, stating that the XSS flaw was only part of the custom implementation of the [polopoly] site. As of 20061003, CVE has no further information on this issue, except that the original researcher has a history of testing live sites and assuming that discoveries indicate vulnerabilities in the associated package

Affected Software

Name Vendor Start Version End Version
Polopoly Polopoly * 9.0 (including)

References