Back

CVE-2005-4385

Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter.

Published: Dec 20, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
cofax cofax 1.9.9c
cofax cofax 1.9.9d
cofax cofax 2.0_rc1
cofax cofax 2.0_rc2
cofax cofax 2.0_rc3

GitHub Security Advisory GHSA-54fx-pxfw-65x8

Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote...

Risk Scores

CVSS Score 4.3 / 10
EPSS Score 8.84%

Top 5% most likely to be exploited

Threat Score 19.9 / 100

Data Sources

NVD EPSS GitHub