VulnerabilityModified
CVE-2005-0883
Multiple cross-site scripting (XSS) vulnerabilities in base.php for DigitalHive 2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the mt parameter to the membres.php page or (2) the -afs-1- query string to the msg.php page.
MEDIUM 4.3EPSS 1.78%
Does this matter?
Lower severity and a low EPSS score (1.78%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in base.php for DigitalHive 2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the mt parameter to the membres.php page or (2) the -afs-1- query string to the msg.php page.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.78% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- digitalhive/digitalhive
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/14702Vendor Advisory
- http://securitytracker.com/id?1013516Vendor Advisory
- http://www.securityfocus.com/bid/12883Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19803
- http://secunia.com/advisories/14702Vendor Advisory
- http://securitytracker.com/id?1013516Vendor Advisory
- http://www.securityfocus.com/bid/12883Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19803
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.