{"api_version":"1","generated_at":"2026-07-23T08:43:52+00:00","cve":"CVE-2005-0784","urls":{"html":"https://cve.report/CVE-2005-0784","api":"https://cve.report/api/cve/CVE-2005-0784.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-0784","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-0784"},"summary":{"title":"CVE-2005-0784","description":"Multiple cross-site scripting (XSS) vulnerabilities in Phorum before 5.0.15 allow remote attackers to inject arbitrary web script or HTML via (1) the subject line to follow.php or (2) the subject line in the user's personal control panel.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-05-02 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=111083279031544&w=2","name":"http://marc.info/?l=bugtraq&m=111083279031544&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'3 XSS Vulnerabilities in Phorum <= 5.0.14' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/14554","name":"http://secunia.com/advisories/14554","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Secunia - Advisories - Phorum Script Insertion Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/12800","name":"http://www.securityfocus.com/bid/12800","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Phorum Multiple Subject and Attachment HTML Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-0784","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-0784","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"784","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phorum","cpe5":"phorum","cpe6":"5.0.14","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:28:28.219Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"12800","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/12800"},{"name":"14554","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/14554"},{"name":"20050313 3 XSS Vulnerabilities in Phorum <= 5.0.14","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=111083279031544&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-03-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Phorum before 5.0.15 allow remote attackers to inject arbitrary web script or HTML via (1) the subject line to follow.php or (2) the subject line in the user's personal control panel."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"12800","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/12800"},{"name":"14554","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/14554"},{"name":"20050313 3 XSS Vulnerabilities in Phorum <= 5.0.14","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=111083279031544&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-0784","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Phorum before 5.0.15 allow remote attackers to inject arbitrary web script or HTML via (1) the subject line to follow.php or (2) the subject line in the user's personal control panel."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"12800","refsource":"BID","url":"http://www.securityfocus.com/bid/12800"},{"name":"14554","refsource":"SECUNIA","url":"http://secunia.com/advisories/14554"},{"name":"20050313 3 XSS Vulnerabilities in Phorum <= 5.0.14","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=111083279031544&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-0784","datePublished":"2005-03-20T05:00:00.000Z","dateReserved":"2005-03-20T00:00:00.000Z","dateUpdated":"2024-08-07T21:28:28.219Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-02 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:phorum:phorum:5.0.14:*:*:*:*:*:*:*","matchCriteriaId":"0FF0655C-7C83-4363-A444-993B35D7A7EA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"784","Ordinal":"1","Title":"CVE-2005-0784","CVE":"CVE-2005-0784","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"784","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Phorum before 5.0.15 allow remote attackers to inject arbitrary web script or HTML via (1) the subject line to follow.php or (2) the subject line in the user's personal control panel.","Type":"Description","Title":"CVE-2005-0784"},{"CveYear":"2005","CveId":"784","Ordinal":"2","NoteData":"2005-03-20","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"784","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}