VulnerabilityModified
CVE-2005-0919
Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.
MEDIUM 4.3EPSS 1.37%
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- adventia/adventia chat · adventia/adventia server pro
- Source
- cve@mitre.org
References
- http://exploitlabs.com/files/advisories/EXPL-A-2005-003-adventiachat.txtVendor Advisory
- http://marc.info/?l=full-disclosure&m=111211930330410&w=2
- http://securitytracker.com/id?1013588Vendor Advisory
- http://www.osvdb.org/15156
- http://www.securityfocus.com/bid/12927Vendor Advisory
- http://www.securityfocus.com/bid/12940
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21317
- http://exploitlabs.com/files/advisories/EXPL-A-2005-003-adventiachat.txtVendor Advisory
- http://marc.info/?l=full-disclosure&m=111211930330410&w=2
- http://securitytracker.com/id?1013588Vendor Advisory
- http://www.osvdb.org/15156
- http://www.securityfocus.com/bid/12927Vendor Advisory
- http://www.securityfocus.com/bid/12940
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21317
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.