CVE-2005-2981

Orion <1.4.5 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.

Scores

EPSS 0.0032
EPSS Percentile 55.1%

Classification

CWE
CWE-79
Status draft

Affected Products (2)

orionserver/orion_application_server
orionserver/orion_application_server

Timeline

Published Sep 20, 2005
Tracked Since Feb 18, 2026