Unrated severityNVD Advisory· Published Apr 27, 2005· Updated Apr 16, 2026
CVE-2005-0085
CVE-2005-0085
Description
Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.
Affected products
27cpe:2.3:a:htdig:htdig:3.1.5:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:htdig:htdig:3.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:htdig:htdig:3.1.5_7:*:*:*:*:*:*:*
- cpe:2.3:a:htdig:htdig:3.1.5_8:*:*:*:*:*:*:*
- cpe:2.3:a:htdig:htdig:3.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:htdig:htdig:3.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:htdig:htdig:3.2.0b2:*:*:*:*:*:*:*
- cpe:2.3:a:htdig:htdig:3.2.0b3:*:*:*:*:*:*:*
- cpe:2.3:a:htdig:htdig:3.2.0b4:*:*:*:*:*:*:*
- cpe:2.3:a:htdig:htdig:3.2.0b5:*:*:*:*:*:*:*
- cpe:2.3:a:htdig:htdig:3.2.0b6:*:*:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux:10.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:mandrakesoft:mandrake_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:mandrakesoft:mandrake_linux:10.0:*:amd64:*:*:*:*:*
- cpe:2.3:o:mandrakesoft:mandrake_linux:10.1:*:*:*:*:*:*:*
- cpe:2.3:o:mandrakesoft:mandrake_linux:10.1:*:x86_64:*:*:*:*:*
cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:*:*:*:*:*:*
- cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:x86_64:*:*:*:*:*
- cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*
- cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:x86_64:*:*:*:*:*
- cpe:2.3:o:redhat:fedora_core:core_3.0:*:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:8.0:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:o:suse:suse_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:8.0:*:i386:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:8.1:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:9.0:*:x86_64:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:9.1:*:*:*:*:*:*:*
- cpe:2.3:o:suse:suse_linux:9.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
18- www.debian.org/security/2005/dsa-680nvdPatchVendor Advisory
- www.securityfocus.com/bid/12442nvdPatchVendor Advisory
- ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.46/SCOSA-2005.46.txtnvd
- secunia.com/advisories/14255nvd
- secunia.com/advisories/14276nvd
- secunia.com/advisories/14303nvd
- secunia.com/advisories/14795nvd
- secunia.com/advisories/15007nvd
- secunia.com/advisories/17414nvd
- secunia.com/advisories/17415nvd
- securitytracker.com/idnvd
- www.gentoo.org/security/en/glsa/glsa-200502-16.xmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00002.htmlnvd
- www.redhat.com/support/errata/RHSA-2005-073.htmlnvd
- www.redhat.com/support/errata/RHSA-2005-090.htmlnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/19223nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10878nvd
News mentions
0No linked articles in our index yet.