Back

CVE-2005-0085

Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.

Published: Apr 27, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (27)

Vendor Product Version
htdig htdig 3.1.5
htdig htdig 3.1.5_7
htdig htdig 3.1.5_8
htdig htdig 3.1.6
htdig htdig 3.2.0
htdig htdig 3.2.0b2
htdig htdig 3.2.0b3
htdig htdig 3.2.0b4
htdig htdig 3.2.0b5
htdig htdig 3.2.0b6
mandrakesoft mandrake_linux 10.0
mandrakesoft mandrake_linux 10.0
mandrakesoft mandrake_linux 10.1
mandrakesoft mandrake_linux 10.1
mandrakesoft mandrake_linux_corporate_server 2.1
mandrakesoft mandrake_linux_corporate_server 2.1
mandrakesoft mandrake_linux_corporate_server 3.0
mandrakesoft mandrake_linux_corporate_server 3.0
redhat fedora_core core_3.0
suse suse_linux 8.0

…and 7 more

GitHub Security Advisory GHSA-qpr6-prp3-323r

Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 2.27%

Top 18% most likely to be exploited

Threat Score 27.9 / 100

Data Sources

NVD EPSS GitHub