CVE-2005-1403
Summary
| CVE | CVE-2005-1403 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-05-03 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php, the (2) currentIsExpanded or (3) searchFor parameters to index.php, (4) the currentNumber parameter to software_CAD_Technical_60002_uk.htm, or (5) a cookie. |
Risk And Classification
Primary CVSS: v2.0 6.8 from [email protected]
AV:N/AC:M/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Just Williams | Amazon Webstore | 04050100 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Just William's Amazon Webstore CurrentNumber Parameter Cross-Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Secunia - Advisories - Amazon Webstore Cross-Site Scripting and HTTP Response Splitting | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Exploit, Vendor Advisory |
| www.osvdb.org/15892 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Just William's Amazon Webstore Closeup.PHP Image Parameter Cross-Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| www.osvdb.org/15894 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Exploit, Vendor Advisory |
| Just William's Amazon Webstore CurrentIsExpanded Parameter Cross-Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Just William's Amazon Webstore SearchFor Parameter Cross-Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Lostmon´s Blogger: Amazon webstore script injection and XSS | af854a3a-2127-422b-91ae-364da2661108 | lostmon.blogspot.com | Exploit |
| www.osvdb.org/15893 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| JustWilliam's Amazon Webstore Input Validation Holes Permit Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.