CVE Database
/

CVE-2005-3496

Back to search

CVE-2005-3496

Published: Nov 4, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in PHP Handicapper allows remote attackers to inject arbitrary web script or HTML via the msg parameter to msg.php. NOTE: some sources identify a second vector in the login parameter to process_signup.php, but the original source says that it is for CRLF injection (CVE-2005-4712). Also note: the vendor has disputed CVE-2005-3497, and it is possible that the dispute was intended to include this issue as well. If so, followup investigation strongly suggests that the original report is correct.

VendorProductVersions

n/a

n/a

affected
n/a

References

20479
vdb-entry
x_refsource_OSVDB
15294
vdb-entry
x_refsource_BID
ADV-2005-2292
vdb-entry
x_refsource_VUPEN
17412
third-party-advisory
x_refsource_SECUNIA
20480
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now