CVE-2005-3867 Information

Description

Cross-site scripting (XSS) vulnerability in RevenuePilot Search Engine Script 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter which is used when performing a search.

Reference

http://pridels0.blogspot.com/2005/11/revenuepilot-search-engine-xss-vuln.html http://secunia.com/advisories/17717 http://www.osvdb.org/21143 http://www.securityfocus.com/bid/15612 http://www.securityfocus.com/bid/16129 http://www.vupen.com/english/advisories/2005/2607 https://exchange.xforce.ibmcloud.com/vulnerabilities/23345

Share on: