peter bassill · operator
$ cve CVE-2005-3959 JSON

CVE-2005-3959 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 4.8% (pctl 92)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in FreeWebStat 1.0 rev37 allow remote attackers to inject arbitrary web script or HTML via the (1) site, (2) jsref, (3) jsres, and (4) jscolor parameters to pixel.php, which are not sanitized before being included in the logdb.html file, and (5) the search key to stat.php.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS4.78% — more likely to be exploited than 92% of all CVEs
On CISA KEVno
Public exploityes
Published2005-12-01
Last modified2026-06-16

Affected (1)

VendorProduct
freewebstatfreewebstat

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD