CVE-2005-3955
Summary
| CVE | CVE-2005-3955 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-12-01 06:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and (c) simple_smarty.php. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Blogbuddies | Blogbuddies | 0.3 | All | All | All |
| Application | Jaws | Jaws | 0.6.2 | All | All | All |
| Application | Magpierss | Magpierss | 7.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Jaws Search Gadget Multiple Input Validation Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - blogBuddies Input Validation Holes Let Remote Users Conduct Cross-Site Scripting Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| www.osvdb.org/21113 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| BlogBuddies Multiple Cross-Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| SourceForge.net: Detail: 1366743 - Patch for Cross-Site Scripting vulnerability in blogBuddies | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Patch |
| Full Disclosure: Feed2JS v1.7 XSS (Cross-site Scripting) Web Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Secunia - Advisories - Jaws Cross-Site Scripting and SQL Injection | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| blogBuddies Cross-Site Scripting Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Error 404 :( | af854a3a-2127-422b-91ae-364da2661108 | retrogod.altervista.org | |
| www.osvdb.org/21112 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Jaws 0.6.3 released | af854a3a-2127-422b-91ae-364da2661108 | www.jaws-project.com | |
| www.osvdb.org/21643 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.