Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2005-3745
Description:Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
Test IDs: 1.3.6.1.4.1.25623.1.0.56375   1.3.6.1.4.1.25623.1.0.117677   1.3.6.1.4.1.25623.1.0.56128  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2005-3745
BugTraq ID: 15512
http://www.securityfocus.com/bid/15512
Bugtraq: 20051121 Security Advisory: Struts Error Message Cross Site Scripting (Google Search)
http://www.securityfocus.com/archive/1/417296/30/0/threaded
http://www.hacktics.com/AdvStrutsNov05.html
https://lists.apache.org/thread.html/r02c2d634fa74209d941c90f9a4cd36a6f12366ca65f9b90446ff2de3@%3Cissues.struts.apache.org%3E
https://lists.apache.org/thread.html/rf482c101a88445d73cc2e89dbf7f16ae00a4aa79a544a1e72b2326db@%3Cissues.struts.apache.org%3E
http://www.osvdb.org/21021
RedHat Security Advisories: RHSA-2006:0157
http://www.redhat.com/support/errata/RHSA-2006-0157.html
RedHat Security Advisories: RHSA-2006:0161
http://www.redhat.com/support/errata/RHSA-2006-0161.html
http://securitytracker.com/id?1015257
http://secunia.com/advisories/17677
http://secunia.com/advisories/18341
http://securityreason.com/securityalert/197
http://www.vupen.com/english/advisories/2005/2525




© 1998-2025 E-Soft Inc. All rights reserved.