Unrated severityNVD Advisory· Published Sep 20, 2005· Updated Apr 16, 2026
CVE-2005-2981
CVE-2005-2981
Description
Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
Affected products
2cpe:2.3:a:orionserver:orion_application_server:1.3.8:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:orionserver:orion_application_server:1.3.8:*:*:*:*:*:*:*
- cpe:2.3:a:orionserver:orion_application_server:1.4.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- marc.infonvdThird Party Advisory
News mentions
0No linked articles in our index yet.