SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-4455

cleanhtml.pl 1.129 in LiveJournal CVS before Dec 13 2005 allows remote attackers to inject scripting languages via the XSL namespace in XML, via vectors such as customview.cgi.

MEDIUM 5.0EPSS 1.04%

Does this matter?

Lower severity and a low EPSS score (1.04%). Track it; it rarely justifies an emergency change on its own.

Description

cleanhtml.pl 1.129 in LiveJournal CVS before Dec 13 2005 allows remote attackers to inject scripting languages via the XSL namespace in XML, via vectors such as customview.cgi.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.04% probability · 62th percentile
CISA KEV
Not listed
Affected
livejournal/livejournal
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.