{"api_version":"1","generated_at":"2026-07-23T05:43:25+00:00","cve":"CVE-2005-0863","urls":{"html":"https://cve.report/CVE-2005-0863","api":"https://cve.report/api/cve/CVE-2005-0863.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-0863","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-0863"},"summary":{"title":"CVE-2005-0863","description":"Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1, chatter2, chatter3, or chatter4 parameters to register.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-05-02 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19748","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19748","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/12841","name":"http://www.securityfocus.com/bid/12841","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHPOpenChat Multiple HTML Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://seclists.org/lists/bugtraq/2005/Mar/0331.html","name":"http://seclists.org/lists/bugtraq/2005/Mar/0331.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bugtraq: Security Contact at RSA?","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://secunia.com/advisories/14651","name":"http://secunia.com/advisories/14651","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - PHPOpenChat Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-0863","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-0863","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"863","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpopenchat","cpe5":"phpopenchat","cpe6":"3.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"863","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpopenchat","cpe5":"phpopenchat","cpe6":"3.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"863","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpopenchat","cpe5":"phpopenchat","cpe6":"3.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:28:28.437Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20050317 [PersianHacker.NET 200503-09]PHPOpenChat v3.x XSS Multiple Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://seclists.org/lists/bugtraq/2005/Mar/0331.html"},{"name":"14651","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/14651"},{"name":"12841","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/12841"},{"name":"phpopenchat-regulars-register-xss(19748)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19748"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-03-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1, chatter2, chatter3, or chatter4 parameters to register.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20050317 [PersianHacker.NET 200503-09]PHPOpenChat v3.x XSS Multiple Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://seclists.org/lists/bugtraq/2005/Mar/0331.html"},{"name":"14651","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/14651"},{"name":"12841","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/12841"},{"name":"phpopenchat-regulars-register-xss(19748)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19748"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-0863","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1, chatter2, chatter3, or chatter4 parameters to register.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20050317 [PersianHacker.NET 200503-09]PHPOpenChat v3.x XSS Multiple Vulnerability","refsource":"BUGTRAQ","url":"http://seclists.org/lists/bugtraq/2005/Mar/0331.html"},{"name":"14651","refsource":"SECUNIA","url":"http://secunia.com/advisories/14651"},{"name":"12841","refsource":"BID","url":"http://www.securityfocus.com/bid/12841"},{"name":"phpopenchat-regulars-register-xss(19748)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19748"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-0863","datePublished":"2005-03-24T05:00:00.000Z","dateReserved":"2005-03-25T00:00:00.000Z","dateUpdated":"2024-08-07T21:28:28.437Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-02 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:phpopenchat:phpopenchat:3.0.0:*:*:*:*:*:*:*","matchCriteriaId":"8893B82A-AA71-45BA-8C50-7D8085C407FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpopenchat:phpopenchat:3.0.1:*:*:*:*:*:*:*","matchCriteriaId":"5C17EFDC-61DA-45EC-AFBD-ECFFA7B55CEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpopenchat:phpopenchat:3.0.2:*:*:*:*:*:*:*","matchCriteriaId":"59390560-5558-434D-ACCE-68EDA977B5CB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"863","Ordinal":"1","Title":"CVE-2005-0863","CVE":"CVE-2005-0863","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"863","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1, chatter2, chatter3, or chatter4 parameters to register.php.","Type":"Description","Title":"CVE-2005-0863"},{"CveYear":"2005","CveId":"863","Ordinal":"2","NoteData":"2005-03-24","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"863","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}