CVE-2005-4460
Summary
| CVE | CVE-2005-4460 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-12-21 20:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Beehive Forum 0.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Description, and (3) Comment fields to (a) links.php and (b) links_add.php. |
Risk And Classification
Primary CVSS: v2.0 5.1 from [email protected]
AV:N/AC:H/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:H/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Beehive Forum | Beehive Forum | 0.1 | All | All | All |
| Application | Beehive Forum | Beehive Forum | 0.1.1 | All | All | All |
| Application | Beehive Forum | Beehive Forum | 0.2 | All | All | All |
| Application | Beehive Forum | Beehive Forum | 0.3 | All | All | All |
| Application | Beehive Forum | Beehive Forum | 0.3.1 | All | All | All |
| Application | Beehive Forum | Beehive Forum | 0.4 | All | All | All |
| Application | Beehive Forum | Beehive Forum | 0.5 | All | All | All |
| Application | Beehive Forum | Beehive Forum | 0.6.2 | All | All | All |
| Application | Beehive Forum | Beehive Forum | 0.6rc1 | All | All | All |
| Application | Beehive Forum | Beehive Forum | 0.6rc2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| cvs.sourceforge.net/viewcvs.py/beehiveforum/beehiveforum/forum/index.php | af854a3a-2127-422b-91ae-364da2661108 | cvs.sourceforge.net | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Beehive Forum Script Insertion Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Beehive Forum Multiple HTML Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.