Back

CVE-2005-4727

Cross-site scripting (XSS) vulnerability in gbook.cgi in gBook before 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header field.

Published: Dec 31, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
martin_bauer gbook 1.0
martin_bauer gbook 1.0.1

GitHub Security Advisory GHSA-gwhh-j9fr-4gcq

Cross-site scripting (XSS) vulnerability in gbook.cgi in gBook before 1.0.2 allows remote...

Risk Scores

CVSS Score 5.1 / 10
EPSS Score 1.72%

Top 24% most likely to be exploited

Threat Score 20.9 / 100

Data Sources

NVD EPSS GitHub