Vulnerability Description
Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow remote attackers to bypass cross-site scripting (XSS) protection via (1) "decimal HTML entities" or (2) "the \x00 symbol."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pixel-Apes Group | Safehtml | 1.3.0 |
References
- http://pixel-apes.com/safehtml/feed
- http://securitytracker.com/id?1013315
- http://pixel-apes.com/safehtml/feed
- http://securitytracker.com/id?1013315
FAQ
What is CVE-2005-0648?
CVE-2005-0648 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow remote attackers to bypass cross-site scripting (XSS) protection via (1) "decimal HTML entities" or (2) "the \x00 symbol."
How severe is CVE-2005-0648?
CVE-2005-0648 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0648?
Check the references section above for vendor advisories and patch information. Affected products include: Pixel-Apes Group Safehtml.