CVE-2005-2336 Affecting hiki package, versions <0.8.2-1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.23% (61st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN8-HIKI-279631
  • published6 Sept 2005
  • disclosed6 Sept 2005

Introduced: 6 Sep 2005

CVE-2005-2336  (opens in a new tab)

How to fix?

Upgrade Debian:8 hiki to version 0.8.2-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream hiki package and not the hiki package as distributed by Debian. See How to fix? for Debian:8 relevant fixed versions and status.

Cross-site scripting (XSS) vulnerability in Hiki 0.8.0 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via "missing pages" in which the page name is not properly escaped, a different vulnerability than CVE-2005-2803.

CVSS Scores

version 3.1