Back
CVE-2005-4385
Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.
Published: Dec 20, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (5)
| Vendor | Product | Version |
|---|---|---|
| cofax | cofax | 1.9.9c |
| cofax | cofax | 1.9.9d |
| cofax | cofax | 2.0_rc1 |
| cofax | cofax | 2.0_rc2 |
| cofax | cofax | 2.0_rc3 |
GitHub Security Advisory GHSA-54fx-pxfw-65x8
Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote...
References (8)
- http://pridels0.blogspot.com/2005/12/cofax-xss-vuln.html
- http://www.osvdb.org/21850
- http://www.securityfocus.com/bid/15940
- http://www.vupen.com/english/advisories/2005/2977
- http://pridels0.blogspot.com/2005/12/cofax-xss-vuln.html
- http://www.osvdb.org/21850
- http://www.securityfocus.com/bid/15940
- http://www.vupen.com/english/advisories/2005/2977
Risk Scores
CVSS Score
4.3 / 10
EPSS Score
8.84%
Top 5% most likely to be exploited
Threat Score
19.9 / 100
Data Sources
NVD
EPSS
GitHub