SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-3496

Cross-site scripting (XSS) vulnerability in PHP Handicapper allows remote attackers to inject arbitrary web script or HTML via the msg parameter to msg.php.

MEDIUM 4.3EPSS 1.97%

Does this matter?

Lower severity and a low EPSS score (1.97%). Track it; it rarely justifies an emergency change on its own.

Description

Cross-site scripting (XSS) vulnerability in PHP Handicapper allows remote attackers to inject arbitrary web script or HTML via the msg parameter to msg.php. NOTE: some sources identify a second vector in the login parameter to process_signup.php, but the original source says that it is for CRLF injection (CVE-2005-4712). Also note: the vendor has disputed CVE-2005-3497, and it is possible that the dispute was intended to include this issue as well. If so, followup investigation strongly suggests that the original report is correct.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.97% probability · 79th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
php handicapper/php handicapper
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.