Secunia Logo
 
CVE Reference: CVE-2005-0085
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-0085

Description:
Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/19223

ST
  1013078

SCO

SAID
  Secunia Advisory: SA15007
  Secunia Advisory: SA14795
  Secunia Advisory: SA14303
  Secunia Advisory: SA14276
  Secunia Advisory: SA17415
  Secunia Advisory: SA17414
  Secunia Advisory: SA14255

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-090.html
  http://www.redhat.com/support/errata/RHSA-2005-073.html

MANDRAKE
  http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:063

GENTOO
  http://www.gentoo.org/security/en/glsa/glsa-200502-16.xml

FEDORA
  http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00002.html

DEBIAN
  http://www.debian.org/security/2005/dsa-680

BID
  12442


Return to the previous page.