← All CVEs

CVE-2005-3388

medium · 4.3

Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."

4.3
CVSS
48.9%
EPSS (exploit prob.)
99th
EPSS percentile
2005-11-01
Published

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

VendorProductAffected versions
phpphp4.0.0
phpphp4.0.1
phpphp4.0.1
phpphp4.0.1
phpphp4.0.2
phpphp4.0.3
phpphp4.0.3
phpphp4.0.4
phpphp4.0.5
phpphp4.0.6
phpphp4.0.7
phpphp4.0.7
phpphp4.0.7
phpphp4.0.7
phpphp4.1.0
phpphp4.1.1
phpphp4.1.2
phpphp4.2
phpphp4.2.0
phpphp4.2.1
phpphp4.2.2
phpphp4.2.3
phpphp4.3.0
phpphp4.3.1
phpphp4.3.2
phpphp4.3.3
phpphp4.3.4
phpphp4.3.5
phpphp4.3.6
phpphp4.3.7
phpphp4.3.8
phpphp4.3.9
phpphp4.3.10
phpphp4.3.11
phpphp4.4.0
phpphp5.0.0
phpphp5.0.0
phpphp5.0.0
phpphp5.0.0
phpphp5.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2005-3388