CVE-2005-3688
Summary
| CVE | CVE-2005-3688 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-11-19 01:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Cross-site scripting (XSS) vulnerability in members.php in XMB 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the "Your Current Mood" field in the registration page. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Xmb Forum | Xmb | 1.8_sp1 | All | All | All |
| Application | Xmb Forum | Xmb | 1.8_sp2 | All | All | All |
| Application | Xmb Forum | Xmb | 1.8_sp3 | All | All | All |
| Application | Xmb Forum | Xmb | 1.9.1 | All | All | All |
| Application | Xmb Forum | Xmb | 1.9.2 | All | All | All |
| Application | Xmb Forum | Xmb | 1.9_beta | All | All | All |
| Application | Xmb Forum | Xmb | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| XMB "Your Current Mood" Script Insertion Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| irannetjob.com - XMB HTML Injection & Path Disclosure | af854a3a-2127-422b-91ae-364da2661108 | irannetjob.com | Exploit, URL Repurposed |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Security Issue History - XMBdocs | af854a3a-2127-422b-91ae-364da2661108 | docs.xmbforum2.com | |
| XMB Forum Member.PHP HTML Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - XMB Forum Input Validation Hole in 'Your Current Mood' Field in the 'member.php' Script Permits Cross-Site Scripting Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| XMB | 2021-04-23 | Robert Chapin | This CVE is considered invalid because it duplicates CVE-2005-0885, "XMB versions 1.9.8 and later were checked and are not vulnerable." Upgrades are available at https://www.xmbforum2.com/ |
There are currently no legacy QID mappings associated with this CVE.