Show plain JSON{"id": "CVE-2005-2416", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2005-08-03T04:00:00.000", "references": [{"url": "http://marc.info/?l=bugtraq&m=112206702015439&w=2", "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/16169", "source": "cve@mitre.org"}, {"url": "http://securitytracker.com/id?1014554", "source": "cve@mitre.org"}, {"url": "http://www.hardened-php.net/advisory_112005.59.html", "tags": ["Exploit", "Patch", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "http://www.osvdb.org/18168", "source": "cve@mitre.org"}, {"url": "http://www.osvdb.org/18169", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/14352", "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21484", "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21487", "source": "cve@mitre.org"}, {"url": "http://marc.info/?l=bugtraq&m=112206702015439&w=2", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://secunia.com/advisories/16169", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://securitytracker.com/id?1014554", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.hardened-php.net/advisory_112005.59.html", "tags": ["Exploit", "Patch", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.osvdb.org/18168", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.osvdb.org/18169", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/14352", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21484", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/21487", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-Other"}]}], "descriptions": [{"lang": "en", "value": "Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module."}, {"lang": "es", "value": "M\u00faltiples vulnerabilidades de secuencias de comandos en sitios cruzados en Contrexx anterior a la 1.0.5 permite que atacantes remotos inyecten script web o HTML mediante el par\u00e1metro \"term\" al m\u00f3dulo de b\u00fasqueda o el t\u00edtulo en el m\u00f3dulo de agregaci\u00f3n de blog."}], "lastModified": "2025-04-03T01:03:51.193", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:astalavista_it_engineering:contrexx:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3B18553E-DB63-4EB4-96AC-FA93E9F11B7A", "versionEndIncluding": "1.0.4"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}