Vulnerability Description
Cross-site scripting (XSS) vulnerability in home/search.php in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the q parameter, as used by the Keyword and Search fields.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Epic Designs | Eggblog | <= 2.0 |
References
- http://pridels0.blogspot.com/2005/12/eggblog-vuln.html
- http://secunia.com/advisories/18212Vendor Advisory
- http://www.osvdb.org/21909
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23856
- http://pridels0.blogspot.com/2005/12/eggblog-vuln.html
- http://secunia.com/advisories/18212Vendor Advisory
- http://www.osvdb.org/21909
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23856
FAQ
What is CVE-2005-4547?
CVE-2005-4547 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in home/search.php in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the q parameter, as used by the Keyword and Search fields.
How severe is CVE-2005-4547?
CVE-2005-4547 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-4547?
Check the references section above for vendor advisories and patch information. Affected products include: Epic Designs Eggblog.