PT-2005-5138 · Unknown · Cleanhtml.Pl
Published
2005-12-21
·
Updated
2008-09-05
·
CVE-2005-4455
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
cleanhtml.pl version 1.129
Description
The issue allows remote attackers to inject scripting languages via the XSL namespace in XML. This can be achieved through vectors such as customview.cgi.
Recommendations
For cleanhtml.pl version 1.129, consider updating to a version released after Dec 13 2005 to resolve the issue. As a temporary workaround, restrict access to customview.cgi to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cleanhtml.Pl