CVE-2005-4262
Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid parameter. NOTE: this issue might be resultant from the SQL injection problem (CVE-2005-4263).
- Affected products
- Evolution
- Envolution
- All versions
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.0% (60th percentile)
- NVD status
- Modified
- Published
- 2005-12-15
CVE-2005-4262 at NVD
1 known exploit for CVE-2005-4262
Proof-of-concept code and exploit modules indexed by Sploitus