Back

CVE-2005-4367

Cross-site scripting (XSS) vulnerability in register_domain.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the "Domain Availability" field. NOTE: this issue was later reported to affect CONTROLzx (renamed from DRZES) 3.3.4.

Published: Dec 20, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
fad_solutions drzes_hms 3.2

GitHub Security Advisory GHSA-6ch8-h5p5-j54q

Cross-site scripting (XSS) vulnerability in register_domain.php in DRZES HMS 3.2 allows remote...

Risk Scores

CVSS Score 5.8 / 10
EPSS Score 1.18%

Top 35% most likely to be exploited

Threat Score 23.6 / 100

Data Sources

NVD EPSS GitHub