CVE-2005-3205
published 2005-10-14CVE-2005-3205: Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web…
PriorityP413low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.60%
73.4th percentile
Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set markup HTML TABLE" command, which is executed when the user selects a table.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hvq8-4qq3-c3ww: Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9
ghsa_unreviewed·2022-05-01
CVE-2005-3205 [LOW] CWE-79 GHSA-hvq8-4qq3-c3ww: Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9
Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set markup HTML TABLE" command, which is executed when the user selects a table.
Red Hat
squid: buffer overflow flaw in Squid's Gopher reply parser (SQUID-2011:3)
vendor_redhat·2011-08-28·CVSS 5.0
CVE-2011-3205 [MEDIUM] squid: buffer overflow flaw in Squid's Gopher reply parser (SQUID-2011:3)
squid: buffer overflow flaw in Squid's Gopher reply parser (SQUID-2011:3)
Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response. NOTE: This issue exists because of a CVE-2005-0094 regression.
Package: squid (Red Hat Enterprise Linux 4) - Not affected
Package: squid (Red Hat Enterprise Linux 5) - Not affected
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0172.htmlhttp://marc.info/?l=bugtraq&m=112870489324437&w=2http://secunia.com/advisories/15991/http://securityreason.com/securityalert/63http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.htmlhttp://www.red-database-security.com/advisory/oracle_isqlplus_css.htmlhttp://www.securityfocus.com/bid/15030https://exchange.xforce.ibmcloud.com/vulnerabilities/22539http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0172.htmlhttp://marc.info/?l=bugtraq&m=112870489324437&w=2http://secunia.com/advisories/15991/http://securityreason.com/securityalert/63http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.htmlhttp://www.red-database-security.com/advisory/oracle_isqlplus_css.htmlhttp://www.securityfocus.com/bid/15030https://exchange.xforce.ibmcloud.com/vulnerabilities/22539
2005-10-14
Published