Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2005-4492
Cross-site scripting (XSS) vulnerability in Starphire SiteSage 5.0.18 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the norelay_highlight_words parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.012
EPSS Ranking
65.2%
CVSS Severity
CVSS v2 Score
4.3
References
http://pridels0.blogspot.com/2005/12/sitesage-xss-vuln.html
http://secunia.com/advisories/18214
http://www.osvdb.org/21861
http://www.securityfocus.com/bid/16017
http://www.vupen.com/english/advisories/2005/3051
http://pridels0.blogspot.com/2005/12/sitesage-xss-vuln.html
http://secunia.com/advisories/18214
http://www.osvdb.org/21861
http://www.securityfocus.com/bid/16017
http://www.vupen.com/english/advisories/2005/3051
Products affected by CVE-2005-4492
Starphire Technologies
»
Sitesage-Ee
»
Version:
Any
cpe:2.3:a:starphire_technologies:sitesage-ee:*
Starphire Technologies
»
Sitesage-Le
»
Version:
Any
cpe:2.3:a:starphire_technologies:sitesage-le:*
Starphire Technologies
»
Sitesage-Sb
»
Version:
Any
cpe:2.3:a:starphire_technologies:sitesage-sb:*
Starphire Technologies
»
Sitesage-Se
»
Version:
Any
cpe:2.3:a:starphire_technologies:sitesage-se:*
Starphire Technologies
»
Sitesage
»
Version:
5.0.18
cpe:2.3:a:starphire_technologies:sitesage:5.0.18
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved