CVE-2005-4284
Cross-site scripting (XSS) vulnerability in StaticStore Search Engine 1.189A and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to search.cgi, possibly the keywords parameter.
Does this matter?
Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in StaticStore Search Engine 1.189A and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to search.cgi, possibly the keywords parameter. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- static store/staticstore
- Source
- cve@mitre.org
References
- http://pridels0.blogspot.com/2005/12/staticstore-search-engine-friendly-e.html
- http://secunia.com/advisories/18037Vendor Advisory
- http://www.osvdb.org/21714
- http://www.osvdb.org/22032
- http://www.securityfocus.com/bid/15895
- http://www.vupen.com/english/advisories/2005/2915
- http://pridels0.blogspot.com/2005/12/staticstore-search-engine-friendly-e.html
- http://secunia.com/advisories/18037Vendor Advisory
- http://www.osvdb.org/21714
- http://www.osvdb.org/22032
- http://www.securityfocus.com/bid/15895
- http://www.vupen.com/english/advisories/2005/2915
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.