VulnerabilityModified
CVE-2005-3908
Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter.
MEDIUM 4.3EPSS 1.89%
Does this matter?
Lower severity and a low EPSS score (1.89%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.89% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- amazon shop/amazon shop
- Source
- cve@mitre.org
References
- http://pridels0.blogspot.com/2005/11/amazon-shop-500-xss-vuln.html
- http://secunia.com/advisories/17750Vendor Advisory
- http://www.attrition.org/pipermail/vim/2007-May/001603.html
- http://www.osvdb.org/21371
- http://www.securityfocus.com/bid/15634Exploit
- http://www.vupen.com/english/advisories/2005/2630
- http://pridels0.blogspot.com/2005/11/amazon-shop-500-xss-vuln.html
- http://secunia.com/advisories/17750Vendor Advisory
- http://www.attrition.org/pipermail/vim/2007-May/001603.html
- http://www.osvdb.org/21371
- http://www.securityfocus.com/bid/15634Exploit
- http://www.vupen.com/english/advisories/2005/2630
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.