CVE-2005-4670

CityPost LNKX - XSS

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in message.php in CityPost Automated Link Exchange (LNKX) allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Thom · textwebappsphp
https://www.exploit-db.com/exploits/25458

References (5)

Core 5
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13255
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1013752
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/20167
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/15676
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15009

Scores

EPSS 0.0053
EPSS Percentile 67.4%

Details

Status published
Products (1)
citypost/php_lnkx 52.0
Published Dec 31, 2005
Tracked Since Feb 18, 2026